Samsung Mobile Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Samsung Mobile products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
13
In CISA KEV
13
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
Samsung Mobile KEVs Added by Year
13 Samsung Mobile KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-21042
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. |
Samsung Mobile Devices | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-21043
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. |
Samsung Mobile Devices | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-25370
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel... |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2021-25369
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2021-25337
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or... |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2023-21492
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. |
Samsung Mobile Devices | Confirmed | In CISA | 19 May 2023 |
|
CVE-2021-25372
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25371
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25395
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25394
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25489
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25487
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2022-22265
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code... |
Samsung Mobile Devices | Confirmed | In CISA | 18 Sep 2023 |
Common Vulnerability Classes (CWE)
- CWE-703 — Improper Check or Handling of Exceptional Conditions 3
- CWE-787 — Out-of-bounds Write 2
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
- CWE-269 — Improper Privilege Management 1
- CWE-362 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') 1
- CWE-416 — Use After Free 1
- CWE-532 — Insertion of Sensitive Information into Log File 1
- CWE-125 — Out-of-bounds Read 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology