Samsung Mobile Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Samsung Mobile products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

13

In CISA KEV

13

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Samsung Mobile KEVs Added by Year

Loading...

13 Samsung Mobile KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-21042

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

Confirmed In CISA 01 Jun 2026
CVE-2025-21043

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

Confirmed In CISA 01 Jun 2026
CVE-2021-25370

An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel...

Confirmed In CISA 08 Nov 2022
CVE-2021-25369

An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

Confirmed In CISA 08 Nov 2022
CVE-2021-25337

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or...

Confirmed In CISA 08 Nov 2022
CVE-2023-21492

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

Confirmed In CISA 19 May 2023
CVE-2021-25372

An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

Confirmed In CISA 29 Jun 2023
CVE-2021-25371

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

Confirmed In CISA 29 Jun 2023
CVE-2021-25395

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is...

Confirmed In CISA 29 Jun 2023
CVE-2021-25394

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio...

Confirmed In CISA 29 Jun 2023
CVE-2021-25489

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string...

Confirmed In CISA 29 Jun 2023
CVE-2021-25487

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in...

Confirmed In CISA 29 Jun 2023
CVE-2022-22265

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code...

Confirmed In CISA 18 Sep 2023

Common Vulnerability Classes (CWE)

  • CWE-703 — Improper Check or Handling of Exceptional Conditions 3
  • CWE-787 — Out-of-bounds Write 2
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
  • CWE-269 — Improper Privilege Management 1
  • CWE-362 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') 1
  • CWE-416 — Use After Free 1
  • CWE-532 — Insertion of Sensitive Information into Log File 1
  • CWE-125 — Out-of-bounds Read 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology