VendorsSamsungandroid16.0
Vulnerabilities

Samsung Android 9.0 16.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

105CVEs
CVE-2026-21105
Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.
Published 2026-09-09 · Analyzed
5.9EPSS 0.001
CVE-2025-21044
Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-10-10 · Analyzed
5.7EPSS 0.001
CVE-2025-21071
Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-11-05 · Analyzed
5.7EPSS 0.001
CVE-2025-21072
Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-12-02 · Analyzed
5.7EPSS 0.001
CVE-2025-58475
Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-12-02 · Analyzed
5.6EPSS 0.001
CVE-2026-20969
Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.
Published 2026-01-09 · Analyzed
5.5EPSS 0.003
CVE-2025-21049
Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
Published 2025-10-10 · Analyzed
5.5EPSS 0.001
CVE-2025-21054
Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.
Published 2025-10-10 · Analyzed
5.5EPSS 0.001
CVE-2025-21028
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
Published 2025-09-03 · Analyzed
5.5EPSS 0.001
CVE-2026-21028
Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-06-05 · Analyzed
5.5EPSS 0.001
CVE-2026-21099
Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-09-09 · Analyzed
5.5EPSS 0.001
CVE-2026-21016
Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-05-13 · Analyzed
5.5EPSS 0.001
CVE-2026-21017
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.
Published 2026-06-05 · Analyzed
5.5EPSS 0.001
CVE-2026-20974
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
Published 2026-01-09 · Analyzed
5.2EPSS 0.002
CVE-2025-21025
Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.
Published 2025-09-03 · Analyzed
5.1EPSS 0.001
CVE-2026-20989
Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.
Published 2026-03-16 · Analyzed
5.1EPSS 0.001
CVE-2025-21027
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.
Published 2025-09-03 · Analyzed
5.1EPSS 0.001
CVE-2026-20972
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
Published 2026-01-09 · Analyzed
4.8EPSS 0.001
CVE-2026-21062
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
Published 2026-08-10 · Analyzed
4.8EPSS 0.001
CVE-2026-20992
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
Published 2026-03-16 · Analyzed
4.8EPSS 0.001
CVE-2026-21027
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
Published 2026-06-05 · Analyzed
4.8EPSS 0.001
CVE-2025-21063
Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen.
Published 2025-10-10 · Analyzed
4.6EPSS 0.002
CVE-2025-58476
Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
4.6EPSS 0.001
CVE-2025-21029
Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2025-21026
Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
← Prev3 / 3