VendorsSamsungandroid15.0
Vulnerabilities

Samsung Android 9.0 15.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

147CVEs
CVE-2025-21028
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
Published 2025-09-03 · Analyzed
5.5EPSS 0.001
CVE-2026-21016
Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-05-13 · Analyzed
5.5EPSS 0.001
CVE-2026-21099
Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-09-09 · Analyzed
5.5EPSS 0.001
CVE-2026-21017
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.
Published 2026-06-05 · Analyzed
5.5EPSS 0.001
CVE-2026-20974
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
Published 2026-01-09 · Analyzed
5.2EPSS 0.002
CVE-2025-20989
Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.
Published 2025-06-04 · Analyzed
5.2EPSS 0.001
CVE-2026-21070
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
Published 2026-08-10 · Analyzed
5.1EPSS 0.002
CVE-2025-20953
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.
Published 2025-05-07 · Analyzed
5.1EPSS 0.001
CVE-2025-20991
Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.
Published 2025-06-04 · Analyzed
5.1EPSS 0.001
CVE-2025-21025
Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.
Published 2025-09-03 · Analyzed
5.1EPSS 0.001
CVE-2025-21027
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.
Published 2025-09-03 · Analyzed
5.1EPSS 0.001
CVE-2026-20972
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
Published 2026-01-09 · Analyzed
4.8EPSS 0.001
CVE-2026-21062
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
Published 2026-08-10 · Analyzed
4.8EPSS 0.001
CVE-2026-20992
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
Published 2026-03-16 · Analyzed
4.8EPSS 0.001
CVE-2026-21027
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
Published 2026-06-05 · Analyzed
4.8EPSS 0.001
CVE-2026-21006
Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.
Published 2026-04-13 · Analyzed
4.7EPSS 0.001
CVE-2025-21063
Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen.
Published 2025-10-10 · Analyzed
4.6EPSS 0.002
CVE-2025-58476
Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
4.6EPSS 0.001
CVE-2025-20942
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.
Published 2025-04-08 · Analyzed
4.4EPSS 0.001
CVE-2025-20958
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.
Published 2025-05-07 · Analyzed
4.4EPSS 0.001
CVE-2025-20999
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
Published 2025-07-08 · Analyzed
4.1EPSS 0.002
CVE-2025-20962
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
Published 2025-05-07 · Analyzed
4.0EPSS 0.001
CVE-2025-20960
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
Published 2025-05-07 · Analyzed
4.0EPSS 0.001
CVE-2025-20990
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
Published 2025-08-06 · Analyzed
4.0EPSS 0.001
CVE-2025-21029
Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2025-21026
Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2025-21046
Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.
Published 2025-10-10 · Analyzed
2.4EPSS 0.002
← Prev4 / 4