Android Applications Updates
SVE-2024-0628(CVE-2025-20913): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0629(CVE-2025-20914): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0630(CVE-2025-20915): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0631(CVE-2025-20916): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in reading string of SPen Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0632(CVE-2025-20917): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in applying binary of pdf content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0633(CVE-2025-20918): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in applying extra data of base content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0634(CVE-2025-20919): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in applying binary of video content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0636(CVE-2025-20920): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in action link data in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0637(CVE-2025-20921): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0661(CVE-2025-20922): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: March 19, 2024
Description: Out-of-bounds read in appending text paragraph in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
The patch adds proper input validation.
SVE-2024-0983(CVE-2025-20923): Improper access control in Galaxy Wearable
Severity: Moderate
Resolved version: 2.2.61.24112961
Reported on: April 20, 2024
Description: Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege.
The patch adds proper access control.
Acknowledgement: Dawuge
SVE-2024-1303(CVE-2025-20927): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: June 17, 2024
Description: Out-of-bounds read in parsing image data in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access out-of-bounds memory.
The patch adds proper length check.
SVE-2024-1426(CVE-2025-20928): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: July 11, 2024
Description: Out-of-bounds read in parsing wbmp image in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access out-of-bounds memory.
The patch adds proper length check.
Acknowledgement: Giovanni Di Santi, Alex Birnberg
SVE-2024-1522(CVE-2025-20924): Improper access control in Samsung Notes
Severity: High
Resolved version: 4.4.26.71
Reported on: July 31, 2024
Description: Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across multiple user profiles.
The patch adds proper access control.
Acknowledgement: Sam of Honor Cyber Security Lab
SVE-2024-1637(CVE-2025-20930, CVE-2025-20929): Out-of-bounds read in Samsung Notes
Severity: High
Resolved version: 4.4.26.71
Reported on: August 19, 2024
Description: Out-of-bounds read and write in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-of-bounds memory and execute arbitrary code.
The patch adds proper input validation.
SVE-2024-1704(CVE-2025-20925): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.26.71
Reported on: August 30, 2024
Description: Out-of-bounds read in applying binary of text data in Samsung Notes prior to version 4.4.26.71 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang @VAR10CK of Baidu Security
SVE-2024-1723(CVE-2025-20933, CVE-2025-20932, CVE-2025-20931): Out-of-bounds read in Samsung Notes
Severity: High
Resolved version: 4.4.26.71
Reported on: September 2, 2024
Description: Out-of-bounds write in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute arbitrary code.
The patch adds proper input validation.
SVE-2024-2146(CVE-2025-20926): Improper export of Android application components in My Files
Severity: Moderate
Resolved version: 15.0.07.5
Reported on: November 11, 2024
Description: Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' privilege.
The patch adds proper access control.
Acknowledgement: Ken Gannon