VendorsSamsungaccountany version
Vulnerabilities

Samsung Account any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2022-30732
Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.
Published 2022-06-07 · Modified
7.5EPSS 0.006
CVE-2022-30735
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.
Published 2022-06-07 · Modified
7.5EPSS 0.004
CVE-2023-21481
Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.
Published 2025-09-03 · Analyzed
7.5EPSS 0.003
CVE-2026-20994
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
Published 2026-03-16 · Analyzed
6.9EPSS 0.001
CVE-2023-42550
Use of implicit intent for sensitive communication vulnerability in startSignIn in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Published 2023-11-07 · Modified
6.5EPSS 0.004
CVE-2023-42549
Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Published 2023-11-07 · Modified
6.5EPSS 0.004
CVE-2023-42548
Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Published 2023-11-07 · Modified
6.5EPSS 0.004
CVE-2023-42547
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Published 2023-11-07 · Modified
6.5EPSS 0.004
CVE-2023-42546
Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Published 2023-11-07 · Modified
6.5EPSS 0.004
CVE-2023-42551
Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Published 2023-11-07 · Modified
6.5EPSS 0.004
CVE-2023-42540
Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.
Published 2023-11-07 · Modified
5.5EPSS 0.002
CVE-2025-58486
Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.
Published 2025-12-02 · Analyzed
5.5EPSS 0.002
CVE-2022-39874
Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
Published 2022-10-07 · Modified
5.5EPSS 0.002
CVE-2024-20841
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.
Published 2024-03-05 · Analyzed
5.5EPSS 0.002
CVE-2025-21076
Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local attackers to access data in Samsung Account. User interaction is required for triggering this vulnerability.
Published 2025-11-05 · Analyzed
5.5EPSS 0.001
CVE-2022-30737
Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.
Published 2022-06-07 · Modified
5.3EPSS 0.005
CVE-2022-30734
Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.
Published 2022-06-07 · Modified
5.3EPSS 0.005
CVE-2022-30733
Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.
Published 2022-06-07 · Modified
5.3EPSS 0.005
CVE-2022-30743
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
Published 2022-06-07 · Modified
5.3EPSS 0.004
CVE-2022-30736
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
Published 2022-06-07 · Modified
5.3EPSS 0.004
CVE-2022-39875
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
Published 2022-10-07 · Modified
5.1EPSS 0.002
CVE-2022-39863
Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permission.
Published 2022-10-07 · Modified
4.7EPSS 0.004
CVE-2022-30739
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.
Published 2022-06-07 · Modified
4.3EPSS 0.004
CVE-2025-58487
Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.
Published 2025-12-02 · Analyzed
4.0EPSS 0.002
CVE-2021-25350
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.
Published 2021-03-25 · Modified
3.9EPSS 0.002
CVE-2021-25403
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.
Published 2021-06-11 · Modified
3.3EPSS 0.002
CVE-2021-25351
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
Published 2021-03-25 · Modified
3.2EPSS 0.003