oversecured GitHub avatar

Samsung_Vulnerabilities

oversecured

Oversecured 公开了一份报告,披露 2022 至 2025 年间在三星预装应用中发现的 176 个漏洞,其中 140 个有详细描述,所有漏洞均已与三星合作修复。

Stars

310

7 天增长

暂无数据

Fork 数

75

开放 Issue

0

开源协议

BSD-2-Clause

最近更新

2026-07-15

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

它展示了对主要移动制造商进行的大规模、持续的安全审计,获得了超过 16.3 万美元的赏金,并位列三星安全研究名人堂榜首。

适合谁使用

  • 移动安全研究人员
  • 三星设备用户
  • Android 应用开发者
  • 企业安全团队

典型使用场景

  • 了解系统应用中的常见漏洞模式
  • 基准测试移动安全扫描器的能力
  • 用于三星设备安全评估的参考
  • 学习真实世界的负责任的披露流程

项目优势

  • 发现 176 个漏洞,140 个有详细描述
  • 与三星的强合作及已验证的修复
  • 展示了 Oversecured 扫描器在处理复杂厂商应用中的有效性
  • 涵盖多种漏洞类型(意图重定向、文件窃取、XSS、SQL 注入等)

使用前须知

  • 仅涵盖三星预装应用,不涉及第三方或其他 OEM 应用
  • 报告为历史数据(2022-2025),漏洞已修复
  • 未提供源代码或扫描方法以供复现

README 快速开始

Responsible disclosure report 2022-2025 - Oversecured found 176 vulnerabilities in Samsung preinstalled apps

Oversecured is a leading mobile security provider specializing in detecting vulnerabilities in Android and iOS apps.

Our team at Oversecured shares global security values and strives to continuously improve our mobile app scanning technology to ensure its excellence.

In this article, we share 176 vulnerabilities that we discovered and worked with Samsung to fix throughout our collaboration, including detailed descriptions of 140 of them.

We at Oversecured are incredibly proud of our collaboration with Samsung in making mobile apps more secure. Our strong partnership with Samsung allows us to work together toward improving global mobile security.

Also, our results demonstrate the capability of our scanner to handle most vulnerabilities where others may fall short. Let’s take a closer look at what we have achieved.

Introduction

Samsung is a leading global electronics company making popular mobile devices based on Android. As a company with a wide range of products, it is unsurprising that they have a vast amount of software code to maintain.

Samsung has one of the most competent cybersecurity teams in the industry, consistently working to improve its security measures. They have implemented various measures to ensure the safety of their users, including a vulnerability disclosure program and regular security audits.

In 2021, Oversecured already conducted a two-week research on Samsung's system app security, which resulted in the discovery of 17 vulnerabilities. We were happy to help Samsung to identify and fix these vulnerabilities, ensuring that their products remain secure for their mobile device users.

Our research 2022-2025 uncovered risky vulnerabilities in Samsung's mobile apps, and we promptly reported them to Samsung's VDP team. We were impressed by Samsung's quick response and efficient handling of the vulnerabilities we reported. As a result, millions of Samsung users can rest assured that their devices are now as secure as those running on AOSP. More details about our research can be found in our [previous article](https://blog.oversecured.com/Discovering-vendor-specific-vulnerabilities-

项目描述

176 vulnerabilities in Samsung preinstalled Android apps

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

makecindy
精选
makecindy GitHub avatar

cindy

Cindy is an open-source AI agent that runs locally on your machine, integrates multiple AI harnesses and models, and provides memory, skills, and automation to perform real work in your projects and apps.

AI 与机器学习大语言模型
958
m-novotny
精选
m-novotny GitHub avatar

memguard-rs

A Rust library that provides secure memory handling primitives including zeroization on drop, memory locking, constant-time comparison, and compile-time guarded regions, with zero dependencies and no_std support.

嵌入式与物联网安全
131
Kritt-ai
Kritt-ai GitHub avatar

open-kritt

open·kritt is an open-source, self-hosted platform that orchestrates AI agents to perform focused, parallel code analysis for finding real vulnerabilities, with de-duplication and validation.

JavaScript
436