ZeroHour

Vulnerabilities

1,623 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21102
Use-after-free in Samsung DualDAR allows local root code execution on Galaxy devices

CVE-2026-21102 is a use-after-free vulnerability in Samsung's DualDAR (Dual Data-at-Rest), the Knox enterprise encryption component used on Galaxy devices in managed enterprise and government deployments. An attacker who already has privileged local access on the device can trigger the flaw in DualDAR and execute arbitrary code with root privileges, gaining full control of the device's encrypted data environment. Affected devices are Samsung Galaxy units where DualDAR is enabled and whose software predates the SMR Sep-2026 Release 1 security maintenance release. The flaw is rated critical (CVSS 4.0: 9.3) because the impact is full compromise (confidentiality, integrity, and availability all high), though exploitation requires local access with high privileges and no user interaction. There are currently no reports of in-the-wild exploitation, no known public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Update affected Galaxy devices to SMR Sep-2026 Release 1 (the September 2026 Samsung security maintenance release) or later, prioritizing enterprise and government fleets where DualDAR is enabled. Use Knox/MDM tooling to inventory devices' current security patch level and confirm whether DualDAR is provisioned, and restrict untrusted local privileged access (e.g., ADB, third-party device-management agents) on unpatched devices. No workarounds are documented; applying the SMR update is the primary mitigation.

9.3
group max
<1%
  • Samsung DualDAR (Dual Data-at-Rest, Knox component on Samsung Galaxy devices) prior to SMR Sep-2026 Release 1
largelikely on the order of 100k–1M DualDAR-enabled Galaxy devices (estimate)
CVE-2026-21079
+3 in the same advisory: …21080 …21083 …21078
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.

Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.

NVD description · AI analysis pending
7.0
group max
<1%
  • samsung smart switch
CVE-2026-21082
+2 in the same advisory: …21077 …21076
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

NVD description · AI analysis pending
6.9<1%
  • samsung health
CVE-2026-21068
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

NVD description · AI analysis pending
8.4
group max
<1%
  • samsung android
CVE-2026-49293
js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec.

js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / binary integer literals via a hand-written `parseBigInt` loop that multiplies a `BigInt` accumulator by the radix once per input digit. Each iteration performs a `BigInt * BigInt` operation on an accumulator that grows linearly with the number of digits already consumed, so the whole loop is O(n²) in the literal length. The lexer regex places no upper bound on the literal length, so a single TOML document containing one ~500 kB hex literal pins one CPU core for ~40 seconds on a modern laptop (Apple M-series, Node v22). Memory amplification is bounded but CPU amplification is severe and grows quadratically: doubling the literal length quadruples the work. A caller that invokes `load()` on attacker-controlled TOML (configuration upload endpoints, CI/CD systems ingesting third-party `*.toml`, IDE plugins, build tools) is exposed to a single-request CPU exhaustion DoS. Version 1.1.1 fixes the issue.

NVD description · AI analysis pending
7.5<1% PoC
  • sunnyadn js-toml
CVE-2026-21038
Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.

Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.

NVD description · AI analysis pending
5.9<1%
  • samsung android usb driver
CVE-2026-21037
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung

Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.

NVD description · AI analysis pending
6.9<1%
  • samsung members
CVE-2026-21036
Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.

Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.

NVD description · AI analysis pending
6.3<1%
  • samsung internet
CVE-2026-21035
Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.

Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.

NVD description · AI analysis pending
6.5<1%
  • samsung plus tv
CVE-2026-21034
Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to ch

Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.

NVD description · AI analysis pending
4.8<1%
  • samsung auto
CVE-2026-21033
+1 in the same advisory: …21032
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arb

Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

NVD description · AI analysis pending
6.9<1%
  • samsung assistant
CVE-2026-21031
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity.

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

NVD description · AI analysis pending
5.2<1%
  • samsung android