VYPR
Vendor

Samsung Account

Products
1
CVEs
27
Across products
27
Status
Private

Products

1

Recent CVEs

27
View all 27 CVEs →
  • CVE-2026-20994MedMar 16, 2026
    risk 0.40cvss 6.1epss 0.00

    URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.

  • CVE-2022-30722MedJun 7, 2022
    risk 0.40cvss 6.2epss 0.00

    Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.

  • CVE-2022-25825MedMar 10, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.

  • CVE-2022-30735MedJun 7, 2022
    risk 0.38cvss 5.9epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.

  • CVE-2025-21076MedNov 5, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local attackers to access data in Samsung Account. User interaction is required for triggering this vulnerability.

  • CVE-2023-42549MedNov 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

  • CVE-2023-42548MedNov 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

  • CVE-2023-42546MedNov 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

  • CVE-2022-30732MedJun 7, 2022
    risk 0.36cvss 5.5epss 0.01

    Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.

  • CVE-2021-25381MedApr 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2023-21481MedSep 3, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.

  • CVE-2022-30743MedJun 7, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

  • CVE-2022-30736MedJun 7, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

  • CVE-2024-20841MedMar 5, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

  • CVE-2022-39875MedOct 7, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

  • CVE-2025-58487MedDec 2, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.

  • CVE-2025-58486MedDec 2, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.

  • CVE-2023-42540MedNov 7, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.

  • CVE-2022-39874MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

  • CVE-2022-30739MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.