415
Total CVEs
174
Critical
90
High
91
Medium
60
Low

Recent CVEs

External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege....

Affected versions: 14.0 15.0 16.0

Published: Apr 13, 2026

3.3

CVSS

Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock....

Affected versions: 14.0 15.0 16.0

Published: Apr 13, 2026

6.8

CVSS

Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions....

Affected versions: 14.0 15.0 16.0

Published: Apr 13, 2026

6.6

CVSS

Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning....

Affected versions: 14.0 15.0 16.0

Published: Apr 13, 2026

6.8

CVSS

Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information....

Affected versions: 14.0 15.0 16.0

Published: Apr 13, 2026

6.5

CVSS

Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard....

Affected versions: 14.0 15.0 16.0

Published: Apr 13, 2026

6.8

CVSS

Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents....

Affected versions: 15.0

Published: Apr 13, 2026

2.4

CVSS

Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions....

Affected versions: 14.0 15.0 16.0

Published: Apr 13, 2026

6.8

CVSS

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution priv...

Affected versions: 14.0 15.0 16.0

Published: Apr 6, 2026

6.2

CVSS

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no a...

Affected versions: -

Published: Apr 6, 2026

5.5

CVSS

Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application....

Affected versions: 13.0 14.0 15.0 16.0

Published: Mar 16, 2026

3.3

CVSS

Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents....

Affected versions: 14.0 15.0 16.0

Published: Mar 16, 2026

4.4

CVSS

Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege....

Affected versions: 14.0 15.0 16.0

Published: Mar 16, 2026

8.1

CVSS

Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font....

Affected versions: 16.0

Published: Mar 16, 2026

2.4

CVSS

Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is requir...

Affected versions: 16.0

Published: Mar 16, 2026

5.0

CVSS

There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...

Affected versions: -

Published: Mar 10, 2026

7.8

CVSS

In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional exec...

Affected versions: -

Published: Mar 10, 2026

8.4

CVSS

In multiple places, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not n...

Affected versions: -

Published: Mar 10, 2026

8.4

CVSS

In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...

Affected versions: -

Published: Mar 10, 2026

2.9

CVSS

In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not nee...

Affected versions: -

Published: Mar 10, 2026

9.8

CVSS

In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This could lead to physical escalation of privilege with no additional execution priv...

Affected versions: -

Published: Mar 10, 2026

6.8

CVSS

In oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...

Affected versions: -

Published: Mar 10, 2026

8.4

CVSS

In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges n...

Affected versions: -

Published: Mar 10, 2026

8.4

CVSS

In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges ...

Affected versions: -

Published: Mar 10, 2026

9.8

CVSS

In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could lead to physical information disclosure with no additional execution privileges ne...

Affected versions: -

Published: Mar 10, 2026

2.1

CVSS

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not nee...

Affected versions: -

Published: Mar 10, 2026

9.8

CVSS

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privi...

Affected versions: -

Published: Mar 10, 2026

9.8

CVSS

In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User inter...

Affected versions: -

Published: Mar 10, 2026

7.4

CVSS

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privi...

Affected versions: -

Published: Mar 10, 2026

9.8

CVSS

In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilege with no additional execution privileges needed. User int...

Affected versions: -

Published: Mar 10, 2026

9.8

CVSS

In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition check failure. This could lead to remote denial of service with no additional execution privileges need...

Affected versions: -

Published: Mar 10, 2026

7.5

CVSS

The register protection of the PowerVR GPU is incorrectly configured. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

Affected versions: -

Published: Mar 10, 2026

4.0

CVSS

In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. This could lead to local escalation of privilege with no additional execution priv...

Affected versions: -

Published: Mar 10, 2026

8.4

CVSS

In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution...

Affected versions: -

Published: Mar 10, 2026

8.4

CVSS

In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. ...

Affected versions: -

Published: Mar 10, 2026

10.0

CVSS

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed....

Affected versions: 13.0 14.0 15.0 16.0

Published: Mar 9, 2026

7.5

CVSS

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed....

Affected versions: 13.0 14.0 15.0 16.0

Published: Mar 9, 2026

7.5

CVSS

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed....

Affected versions: 13.0 14.0 15.0 16.0

Published: Mar 9, 2026

7.5

CVSS

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed....

Affected versions: 13.0 14.0 15.0 16.0

Published: Mar 9, 2026

7.5

CVSS

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed....

Affected versions: 13.0 14.0 15.0 16.0

Published: Mar 9, 2026

7.5

CVSS

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed....

Affected versions: 13.0 14.0 15.0 16.0

Published: Mar 9, 2026

7.5

CVSS

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed....

Affected versions: 13.0 14.0 15.0 16.0

Published: Mar 9, 2026

7.5

CVSS

In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege...

Affected versions: 16.0

Published: Mar 2, 2026

8.4

CVSS

In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional executio...

Affected versions: -

Published: Mar 2, 2026

8.4

CVSS

In multiple functions of ffa.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed....

Affected versions: -

Published: Mar 2, 2026

8.4

CVSS

In createRequest of MediaProvider.java, there is a possible way for an app to gain read/write access to non-existing files due to a logic error in the code. This could lead to local escalation of priv...

Affected versions: 14.0 15.0 16.0

Published: Mar 2, 2026

8.4

CVSS

In setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. This could lead to local escalation of privilege with no addit...

Affected versions: 14.0 15.0 16.0

Published: Mar 2, 2026

8.4

CVSS

In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileg...

Affected versions: -

Published: Mar 2, 2026

7.8

CVSS

In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges nee...

Affected versions: -

Published: Mar 2, 2026

8.4

CVSS

In __host_check_page_state_range of mem_protect.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional executi...

Affected versions: -

Published: Mar 2, 2026

8.4

CVSS