Samsung
Samsung Health: vulnerabilities and CVEs
Samsung Health has 15 published vulnerabilities, 5 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs15
Last 12 months5
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21082 | Medium (6.9) | 0.17% | — | Aug 10, 2026 | Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |
| CVE-2026-21077 | Medium (6.9) | 0.13% | — | Aug 10, 2026 | Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |
| CVE-2026-21076 | Medium (6.9) | 0.13% | — | Aug 10, 2026 | Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. |
| CVE-2026-21056 | Medium (4.8) | 0.13% | — | Jul 10, 2026 | Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information. |
| CVE-2025-21059 | Medium (5.5) | 0.12% | — | Oct 10, 2025 | Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health. |
| CVE-2025-21019 | Medium (5.5) | 0.14% | — | Aug 6, 2025 | Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability. |
| CVE-2024-34597 | Low (3.3) | 0.15% | — | Jul 2, 2024 | Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this… |
| CVE-2023-42539 | Medium (5.5) | 0.16% | — | Nov 7, 2023 | PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data. |
| CVE-2023-30737 | Medium (5.5) | 0.17% | — | Oct 4, 2023 | Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent. |
| CVE-2023-30734 | Medium (5.5) | 0.17% | — | Oct 4, 2023 | Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent. |
| CVE-2023-30723 | Critical (9.8) | 0.40% | — | Sep 6, 2023 | Improper input validation vulnerability in Samsung Health prior to version 6.24.2.011 allows attackers to write arbitrary file with Samsung Health privilege. |
| CVE-2022-22283 | Low (3.3) | 0.20% | — | Jan 10, 2022 | Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App. |
| CVE-2021-25506 | Medium (5.5) | 0.20% | — | Nov 5, 2021 | Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service. |
| CVE-2021-25425 | Medium (5.3) | 0.79% | — | Jun 11, 2021 | Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component. |
| CVE-2021-25401 | High (7.8) | 0.26% | — | Jun 11, 2021 | Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action. |