oversecured GitHub avatar

Samsung_Vulnerabilities

oversecured

Oversecured discloses a report of 176 vulnerabilities discovered in Samsung preinstalled apps between 2022 and 2025, with 140 detailed, all fixed in collaboration with Samsung.

Stars

310

7-day growth

No data

Forks

75

Open issues

0

License

BSD-2-Clause

Last updated

2026-07-15

AI repository intelligence
FR-AI / ANALYSIS

Why it is worth attention

It showcases a sustained, large-scale security audit of a major mobile manufacturer, resulting in over $163,000 in bounties and top ranking in Samsung's security research hall of fame.

Who it is for

  • mobile security researchers
  • Samsung device users
  • Android app developers
  • enterprise security teams

Use cases

  • understanding common vulnerability patterns in system apps
  • benchmarking mobile security scanner capabilities
  • informing Samsung device security assessments
  • learning from real-world responsible disclosure processes

Strengths

  • 176 vulnerabilities found, with 140 detailed descriptions
  • strong partnership with Samsung and verified fixes
  • demonstrates Oversecured scanner's effectiveness in complex vendor apps
  • includes diverse vulnerability types (intent redirection, file theft, XSS, SQL injection, etc.)

Considerations

  • only covers Samsung preinstalled apps, not third-party or other OEM apps
  • report is historical (2022-2025) and vulnerabilities are already fixed
  • no source code or scanning methodology provided for replication

README quick start

Responsible disclosure report 2022-2025 - Oversecured found 176 vulnerabilities in Samsung preinstalled apps

Oversecured is a leading mobile security provider specializing in detecting vulnerabilities in Android and iOS apps.

Our team at Oversecured shares global security values and strives to continuously improve our mobile app scanning technology to ensure its excellence.

In this article, we share 176 vulnerabilities that we discovered and worked with Samsung to fix throughout our collaboration, including detailed descriptions of 140 of them.

We at Oversecured are incredibly proud of our collaboration with Samsung in making mobile apps more secure. Our strong partnership with Samsung allows us to work together toward improving global mobile security.

Also, our results demonstrate the capability of our scanner to handle most vulnerabilities where others may fall short. Let’s take a closer look at what we have achieved.

Introduction

Samsung is a leading global electronics company making popular mobile devices based on Android. As a company with a wide range of products, it is unsurprising that they have a vast amount of software code to maintain.

Samsung has one of the most competent cybersecurity teams in the industry, consistently working to improve its security measures. They have implemented various measures to ensure the safety of their users, including a vulnerability disclosure program and regular security audits.

In 2021, Oversecured already conducted a two-week research on Samsung's system app security, which resulted in the discovery of 17 vulnerabilities. We were happy to help Samsung to identify and fix these vulnerabilities, ensuring that their products remain secure for their mobile device users.

Our research 2022-2025 uncovered risky vulnerabilities in Samsung's mobile apps, and we promptly reported them to Samsung's VDP team. We were impressed by Samsung's quick response and efficient handling of the vulnerabilities we reported. As a result, millions of Samsung users can rest assured that their devices are now as secure as those running on AOSP. More details about our research can be found in our [previous article](https://blog.oversecured.com/Discovering-vendor-specific-vulnerabilities-

Description

176 vulnerabilities in Samsung preinstalled Android apps

Related repositories

Similar projects matched by category, topics, and programming language.

makecindy
Featured
makecindy GitHub avatar

cindy

Cindy is an open-source AI agent that runs locally on your machine, integrates multiple AI harnesses and models, and provides memory, skills, and automation to perform real work in your projects and apps.

AI & Machine LearningLarge Language Models
958
m-novotny
Featured
m-novotny GitHub avatar

memguard-rs

A Rust library that provides secure memory handling primitives including zeroization on drop, memory locking, constant-time comparison, and compile-time guarded regions, with zero dependencies and no_std support.

Embedded & IoTSecurity
131
Kritt-ai
Kritt-ai GitHub avatar

open-kritt

open·kritt is an open-source, self-hosted platform that orchestrates AI agents to perform focused, parallel code analysis for finding real vulnerabilities, with de-duplication and validation.

JavaScript
436