Vulnerabilities
1,623 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21102 | Use-after-free in Samsung DualDAR allows local root code execution on Galaxy devices CVE-2026-21102 is a use-after-free vulnerability in Samsung's DualDAR (Dual Data-at-Rest), the Knox enterprise encryption component used on Galaxy devices in managed enterprise and government deployments. An attacker who already has privileged local access on the device can trigger the flaw in DualDAR and execute arbitrary code with root privileges, gaining full control of the device's encrypted data environment. Affected devices are Samsung Galaxy units where DualDAR is enabled and whose software predates the SMR Sep-2026 Release 1 security maintenance release. The flaw is rated critical (CVSS 4.0: 9.3) because the impact is full compromise (confidentiality, integrity, and availability all high), though exploitation requires local access with high privileges and no user interaction. There are currently no reports of in-the-wild exploitation, no known public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Update affected Galaxy devices to SMR Sep-2026 Release 1 (the September 2026 Samsung security maintenance release) or later, prioritizing enterprise and government fleets where DualDAR is enabled. Use Knox/MDM tooling to inventory devices' current security patch level and confirm whether DualDAR is provisioned, and restrict untrusted local privileged access (e.g., ADB, third-party device-management agents) on unpatched devices. No workarounds are documented; applying the SMR update is the primary mitigation. | 9.3 group max | <1% |
| largelikely on the order of 100k–1M DualDAR-enabled Galaxy devices (estimate) | ||
| CVE-2026-21079 | Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. NVD description · AI analysis pending | 7.0 group max | <1% |
| — | ||
| CVE-2026-21082 | Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2026-21068 | Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. NVD description · AI analysis pending | 8.4 group max | <1% |
| — | ||
| CVE-2026-49293 | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / binary integer literals via a hand-written `parseBigInt` loop that multiplies a `BigInt` accumulator by the radix once per input digit. Each iteration performs a `BigInt * BigInt` operation on an accumulator that grows linearly with the number of digits already consumed, so the whole loop is O(n²) in the literal length. The lexer regex places no upper bound on the literal length, so a single TOML document containing one ~500 kB hex literal pins one CPU core for ~40 seconds on a modern laptop (Apple M-series, Node v22). Memory amplification is bounded but CPU amplification is severe and grows quadratically: doubling the literal length quadruples the work. A caller that invokes `load()` on attacker-controlled TOML (configuration upload endpoints, CI/CD systems ingesting third-party `*.toml`, IDE plugins, build tools) is exposed to a single-request CPU exhaustion DoS. Version 1.1.1 fixes the issue. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2026-21038 | Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory. Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory. NVD description · AI analysis pending | 5.9 | <1% |
| — | ||
| CVE-2026-21037 | Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2026-21036 | Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. NVD description · AI analysis pending | 6.3 | <1% |
| — | ||
| CVE-2026-21035 | Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information. Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-21034 | Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to ch Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2026-21033 +1 in the same advisory: …21032 | Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arb Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2026-21031 | Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability. NVD description · AI analysis pending | 5.2 | <1% |
| — |