Samsung vulnerabilities
14 CVEs tracked
Samsung features prominently in this week's reports due to a privacy backlash and critical vulnerabilities with potential for active exploitation. Key incidents include a $50,000 exploit chain that leveraged flaws in the Samsung Members and Samsung Account applications to turn Bixby against Samsung phones. Highlighted vulnerabilities include CVE-2026-21082 (relative path traversal) and CVE-2026-21077 (incorrect authorization) in Samsung Health, allowing local attackers to access sensitive information, and CVE-2026-21081 in SamsungPassAutofill. Defenders should immediately prioritize patching for Samsung Health, SamsungPassAutofill, and the rlottie library to mitigate local information disclosure and input validation risks.
Azərbaycanca: Samsung bu həftə hesabatlarımızda həm məxfilik qalmaqalı, həm də aktiv istismar potensialı olan kritik zəifliklərlə bağlı önə çıxır. Əsas hadisələrə 'Samsung Members' və 'Samsung Account' tətbiqlərindəki boşluqlar zəncirindən istifadə edərək Bixby vasitəsilə telefonu ələ keçirməyə imkan verən $50,000 dəyərində istismar zənciri daxildir. Qeyd olunan zəifliklər arasında 'Samsung Health' tətbiqində həssas məlumatlara çıxışa səbəb ola biləcək CVE-2026-21082 (relative path traversal) və CVE-2026-21077 (yanlış avtorizasiya), həmçinin 'SamsungPassAutofill'də CVE-2026-21081 xüsusilə diqqət çəkir. Müdafiəçilər dərhal 'Samsung Health', 'SamsungPassAutofill' və 'rlottie' kitabxanası üçün təhlükəsizlik yeniləmələrini tətbiq etməli, köhnə versiyalarda həssas məlumat sızması riskinə qarşı tədbir görməlidir.
This vendor's CVEs14
- CVE-2026-21082EPSS 0.12%
- CVE-2026-21081EPSS 0.09%
- CVE-2026-21077EPSS 0.09%
- CVE-2026-21076EPSS 0.09%
- CVE-2026-21070EPSS 0.14%
- CVE-2026-21061EPSS 0.29%
- CVE-2026-21060EPSS 0.15%
- CVE-2026-21059EPSS 0.09%
- CVE-2026-21058EPSS 0.10%
- CVE-2026-19588EPSS 0.20%
- CVE-2026-19587EPSS 0.20%
- CVE-2026-19518EPSS 0.20%
- CVE-2026-19517EPSS 0.20%
- CVE-2026-18772EPSS 0.20%
This hub is built from skopnix's own reporting on Samsung: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.