Aggregates CVE and security vulnerability intelligence across all Samsung-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk input validation and vendor risk cross-site scripting and related security problems, affecting vendor surface production workloads and vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-21038 | Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory. | [email protected] | 5.9 | 0.11% | 2026-06-05 | 2026-06-30 |
| CVE-2026-21037 | Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege. | [email protected] | 6.9 | 0.11% | 2026-06-05 | 2026-06-30 |
| CVE-2026-21036 | Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. | [email protected] | 6.3 | 0.10% | 2026-06-05 | 2026-06-30 |
| CVE-2026-21035 | Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information. | [email protected] | 6.5 | 0.31% | 2026-06-05 | 2026-06-30 |
| CVE-2026-21034 | Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration. | [email protected] | 4.8 | 0.09% | 2026-06-05 | 2026-06-30 |
| CVE-2026-21033 | Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | [email protected] | 6.9 | 0.09% | 2026-06-05 | 2026-06-17 |
| CVE-2026-21032 | Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | [email protected] | 6.9 | 0.09% | 2026-06-05 | 2026-06-17 |
| CVE-2026-21031 | Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability. | [email protected] | 5.2 | 0.09% | 2026-06-05 | 2026-06-17 |
| CVE-2026-21030 | Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions. | [email protected] | 6.4 | 0.09% | 2026-06-05 | 2026-06-17 |
| CVE-2026-21029 | Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations. | [email protected] | 6.8 | 0.09% | 2026-06-05 | 2026-06-17 |
| CVE-2026-21028 | Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | [email protected] | 5.1 | 0.09% | 2026-06-05 | 2026-06-17 |
| CVE-2026-21027 | Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function. | [email protected] | 4.8 | 0.08% | 2026-06-05 | 2026-06-17 |
| CVE-2026-21026 | Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information. | [email protected] | 6.4 | 0.09% | 2026-06-05 | 2026-06-17 |
| CVE-2026-21025 | Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | [email protected] | 6.9 | 0.09% | 2026-06-05 | 2026-06-17 |
| CVE-2026-21017 | Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files. | [email protected] | 4.6 | 0.09% | 2026-06-05 | 2026-06-17 |
| CVE-2026-8915 | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31. | [email protected] | 8.8 | 0.32% | 2026-05-27 | 2026-06-17 |
| CVE-2026-47317 | Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | [email protected] | 5.5 | 0.27% | 2026-05-19 | 2026-06-17 |
| CVE-2026-47316 | Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | [email protected] | 5.5 | 0.27% | 2026-05-19 | 2026-06-17 |
| CVE-2026-47315 | Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | [email protected] | 5.5 | 0.27% | 2026-05-19 | 2026-06-17 |
| CVE-2026-47314 | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3. | [email protected] | 7.8 | 0.29% | 2026-05-19 | 2026-06-17 |