VendorsSamsungandroidall versions
Vulnerabilities

Samsung Android 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

511CVEs
CVE-2023-30718
Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.
Published 2023-09-06 · Modified
4.0EPSS 0.001
CVE-2025-20962
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
Published 2025-05-07 · Analyzed
4.0EPSS 0.001
CVE-2024-20860
Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.
Published 2024-05-07 · Analyzed
4.0EPSS 0.001
CVE-2024-34677
Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.
Published 2024-11-06 · Analyzed
4.0EPSS 0.001
CVE-2024-20847
Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard information.
Published 2024-04-02 · Analyzed
4.0EPSS 0.001
CVE-2024-20900
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
Published 2024-07-02 · Modified
4.0EPSS 0.001
CVE-2024-34650
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
Published 2024-09-04 · Analyzed
4.0EPSS 0.001
CVE-2024-34583
Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.
Published 2024-07-02 · Modified
4.0EPSS 0.001
CVE-2024-34652
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
Published 2024-09-04 · Analyzed
4.0EPSS 0.001
CVE-2024-34618
Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.
Published 2024-08-07 · Analyzed
4.0EPSS 0.001
CVE-2023-21471
Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2024-34617
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.
Published 2024-08-07 · Analyzed
4.0EPSS 0.001
CVE-2025-20960
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
Published 2025-05-07 · Analyzed
4.0EPSS 0.001
CVE-2023-21470
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2023-21469
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2025-20990
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
Published 2025-08-06 · Analyzed
4.0EPSS 0.001
CVE-2025-21029
Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2025-21026
Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2023-21512
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.
Published 2023-06-28 · Modified
3.3EPSS 0.002
CVE-2024-20810
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.
Published 2024-02-06 · Modified
3.3EPSS 0.002
CVE-2023-21452
Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
Published 2023-03-16 · Modified
3.3EPSS 0.002
CVE-2023-21436
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
Published 2023-02-09 · Modified
3.3EPSS 0.002
CVE-2024-20834
The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.
Published 2024-03-05 · Analyzed
3.3EPSS 0.001
CVE-2024-34640
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
Published 2024-09-04 · Analyzed
3.3EPSS 0.001
CVE-2024-20855
Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.
Published 2024-05-07 · Analyzed
2.4EPSS 0.002
CVE-2023-21454
Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.
Published 2023-03-16 · Modified
2.4EPSS 0.002
CVE-2023-21438
Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.
Published 2023-02-09 · Modified
2.4EPSS 0.002
CVE-2024-49414
Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.
Published 2024-12-03 · Analyzed
2.4EPSS 0.002
CVE-2024-34649
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.
Published 2024-09-04 · Analyzed
2.4EPSS 0.002
CVE-2024-34682
Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi password in Maintenance Mode.
Published 2024-11-06 · Analyzed
2.4EPSS 0.002
CVE-2025-21046
Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.
Published 2025-10-10 · Analyzed
2.4EPSS 0.002
← Prev13 / 13