« Volver al listado

Samsung

Samsung Android: vulnerabilidades y CVE

Samsung Android tiene 502 vulnerabilidades publicadas, 102 de ellas en los últimos 12 meses. 12 son críticas y 12 figuran en el catálogo de explotación activa de CISA.

CVE502
Últimos 12 meses102
Críticas12
Explotadas activamente12

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-21042Crítica (9.8)33%⚠ Explotación activa12 sept 2025
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
CVE-2025-21043Crítica (9.8)2.1%⚠ Explotación activa12 sept 2025
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
CVE-2021-25487Alta (7.8)0.64%⚠ Explotación activa6 oct 2021
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
CVE-2021-25489Media (5.5)0.53%⚠ Explotación activa6 oct 2021
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
CVE-2021-25372Media (6.7)0.80%⚠ Explotación activa26 mar 2021
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
CVE-2021-25371Media (6.7)0.80%⚠ Explotación activa26 mar 2021
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
CVE-2021-25394Media (6.4)0.40%⚠ Explotación activa11 jun 2021
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
CVE-2021-25395Media (6.4)0.37%⚠ Explotación activa11 jun 2021
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
CVE-2023-21492Media (4.4)2.6%⚠ Explotación activa4 may 2023
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
CVE-2021-25337Alta (7.1)2.8%⚠ Explotación activa4 mar 2021
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
CVE-2021-25369Media (5.5)1.1%⚠ Explotación activa26 mar 2021
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
CVE-2021-25370Media (4.4)0.89%⚠ Explotación activa26 mar 2021
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21112Media (5.1)0.09%—9 sept 2026
Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.
CVE-2026-21104Alta (7.1)0.10%—9 sept 2026
Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.
CVE-2026-21103Media (6.8)0.18%—9 sept 2026
Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.
CVE-2026-21102Crítica (9.3)0.12%—9 sept 2026
Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.
CVE-2026-21101Alta (8.4)0.12%—9 sept 2026
Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.
CVE-2026-21100Media (6.9)0.09%—9 sept 2026
Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.
CVE-2026-21099Media (5.1)0.09%—9 sept 2026
Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
CVE-2026-21098Media (6.9)0.09%—9 sept 2026
Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction.
CVE-2026-21097Media (4.6)0.12%—9 sept 2026
Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.
CVE-2026-21096Crítica (9.2)0.46%—9 sept 2026
Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
CVE-2026-21095Crítica (9.2)0.46%—9 sept 2026
Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
CVE-2026-21094Media (6.1)0.16%—9 sept 2026
Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.
CVE-2026-21093Media (5.6)0.09%—9 sept 2026
Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
CVE-2026-21092Alta (8.8)0.32%—9 sept 2026
Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.
CVE-2026-21091Media (4.8)0.10%—9 sept 2026
Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21090Media (4.8)0.10%—9 sept 2026
Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21089Media (6.9)0.10%—9 sept 2026
Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21088Media (6.9)0.11%—9 sept 2026
Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21087Alta (8.6)0.12%—9 sept 2026
Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.
CVE-2026-21086Media (4.8)0.11%—9 sept 2026
Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.
CVE-2026-21085Alta (8.4)0.11%—9 sept 2026
Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
CVE-2026-21073Media (5.2)0.21%—10 ago 2026
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
CVE-2026-21072Media (5.1)0.15%—10 ago 2026
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21071Media (5.1)0.15%—10 ago 2026
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21070Media (5.1)0.21%—10 ago 2026
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
CVE-2026-21069Media (5.1)0.15%—10 ago 2026
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21068Alta (8.4)0.17%—10 ago 2026
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
CVE-2026-21067Media (5.1)0.15%—10 ago 2026
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21066Media (5.1)0.15%—10 ago 2026
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21065Media (4.8)0.15%—10 ago 2026
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation10
  2. T1059 Command and Scripting Interpreter4
  3. T1190 Exploit Public-Facing Application2
  4. T1499.004 Application or System Exploitation2
  5. T1005 Data from Local System1
  6. T1052.001 Exfiltration over USB1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Samsung