📦

android

Vendor: samsung

Actively Exploited 25 CISA KEV List
PoC / Exploits 312 Code Available
Total RCEs 849 Remote Access
Total CVEs 601 Total Indexed
Avg. EPSS 0.55% Exploit Prob.
Latest CVE CVE-2026-21031 Jun 05

Security Vulnerability Index

Page 1 / 61
5.2 CVSS

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

EPSS: 0.09%
6.4 CVSS

Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.

EPSS: 0.09%
6.8 CVSS

Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

EPSS: 0.09%
5.1 CVSS

Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

EPSS: 0.09%
4.8 CVSS

Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

EPSS: 0.08%
6.4 CVSS

Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.

EPSS: 0.09%
6.9 CVSS

Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

EPSS: 0.09%
4.6 CVSS

Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.

EPSS: 0.09%
3.3 CVSS

In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS: 0.06%
4.0 CVSS

In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.

EPSS: 0.07%