Open-source project
oversecured/Samsung_Vulnerabilities avatar
oversecured/Samsung_Vulnerabilities

Oversecured's Samsung_Vulnerabilities: a public index of 176 fixed Android flaws

176 vulnerabilities in Samsung preinstalled Android apps

352 stars90 forksJavaBSD-2-Clause

At a glance

What is it?
The repository is a disclosure archive, not a scanner: one folder per reported vulnerability in Samsung preinstalled apps, with detailed write-ups for 140 of them. It is useful as reading material and as a bug-class catalogue, and it will not patch anything for you.
Who is it for?
Adopt this repository as a reading archive if you build or audit Android system apps and want a catalogue of real bug classes: intent redirection, arbitrary content provider access, token leakage, file overwrite with system privilege. Do not adopt it if you need a scanner, a patch, or per-device status, because the repository ships prose and no tooling, and the README states all listed vulnerabilities are already fixed with Oversecured's help.
Can I use it commercially?
Yes. BSD-2-Clause is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 76 days ago.
What is it written in?
Mainly Java, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the Samsung_Vulnerabilities repository actually is

This is a disclosure report published as a repository. The README describes 176 vulnerabilities that Oversecured found in Samsung preinstalled Android apps and worked with Samsung to fix between 2022 and 2025, with detailed descriptions for 140 of them. Each entry is a numbered directory at the top level, named after the affected app and the bug: for example "001. Settings: Intent redirection with system privilege", "015. DualOutFocusViewer: Arbitrary code execution", "039. Samsung Cloud: Leakage of auth tokens, purchase history, and last 4 numbers of credit card".

The audience is narrow but real. Android security engineers, OEM system app developers, and bug bounty hunters read archives like this to learn which classes of mistake keep appearing in privileged code. The README also states that Samsung rewarded the team $163.475 and ranked it first in Samsung's security research ranking at publication time. That figure is a statement about the programme, not a measure of the repository's quality, and it is not a reason to adopt anything.

The repository is not archived, and the last push was on 2026-07-15. There are no releases. It is a document collection, so the absence of releases is expected rather than a warning sign.

How the disclosure archive is laid out and how entries read

The mechanism is a flat directory per finding, numbered from 001 upward, with the app name and the vulnerability class in the folder name. The README table repeats that structure as a table with three columns: number, app, description, plus a reward column in US dollars. The table is sorted by date of report and fix, so reading it top to bottom is roughly a chronology of the 2022-2025 collaboration.

Inside a folder, the material is a write-up, not code you run. The README links each table row to its directory, and describes a separate Oversecured blog article for the most interesting findings. If you want exploit mechanics, the folder prose is where they live; if you want a one-line index, the README table is enough.

The coverage is broad across Samsung's preinstalled surface: Settings, Galaxy Store, Galaxy Themes, SmartThings, Samsung Cloud, Samsung Pay, Samsung Internet Browser, Quick Share, Knox VPN Services, DeX, Bixby Vision, and more. Recurring classes include intent redirection, access to arbitrary content providers with system privilege, token leakage, and overwriting or theft of arbitrary files. That repetition is the useful signal: the same mistakes recur across teams and apps.

Reading the Samsung vulnerability list without installing anything

There is no install step, because there is no software. The repository is Java-labelled in its metadata, but the deliverable is documentation. The README gives no build instructions, no package name, and no command to run. What you can do is open the repository and browse the numbered directories.

The README does not provide a clone command, so the only concrete instruction available is the one the README itself gives: read the list of vulnerabilities, which is presented as a table with a number, an app, a description, and a reward for each entry. The table is the fastest way to scan all 176 entries. Open a specific numbered directory when you want the full description of one finding.

If you are looking for a scanner to point at an APK, this repository is the wrong artefact. The README describes Oversecured as a mobile security provider whose scanner found these issues, but the scanner itself is not in this repository.

What the archive does not give you

There is no mapping from a finding to a patch level, build number, or security bulletin. The README states that all listed vulnerabilities are already fixed with Oversecured's help, and that the list is sorted by date of report and fix, but it does not say which firmware release carries each fix. If you are checking whether a specific device is exposed, this repository cannot answer that; Samsung's own security bulletin is the source for patch levels.

There is also no reproducibility material in the form of a harness, test app, or proof-of-concept you can run. The write-ups describe the issues; they are not an exploit toolkit, and treating them as one is both wrong and unnecessary since the fixes are in.

The third gap is scope. This is Samsung preinstalled apps, not AOSP, not third-party apps, and not the kernel or baseband. A finding in Galaxy Store tells you nothing directly about a non-Samsung Android build. If your product is not an OEM system app suite, most entries here are case studies rather than a checklist for your codebase.

Where an archive like this fits next to a real scanner

The obvious alternative is a static analysis tool you run yourself, such as MobSF or a commercial Android SAST product. The difference in approach is fundamental: this repository is a retrospective, human-written record of findings that have already been fixed, while a scanner is a prospective tool that inspects an APK or source tree you supply and reports what it finds now.

A scanner gives you coverage of your own code and a repeatable result you can put in a pipeline. It also gives you false positives, triage work, and no narrative about why a pattern is dangerous. This repository gives you the narrative and the concrete consequence, for example that an intent redirection in Settings can reach system privilege, but it cannot look at your app.

The two are complementary in one specific way: the recurring classes in this archive (intent redirection, arbitrary content provider access, token leakage in broadcasts) are exactly the rules you would want enabled and tuned in a scanner. Reading the archive first tells you which rules matter for privileged Android code; the scanner then applies them at scale.

Maintenance, licence, and what an archive costs to keep

The repository is not archived, and the last push was on 2026-07-15, so it is not a frozen artefact, but the README frames the work as a completed 2022-2025 disclosure effort rather than an ongoing feed. There are no releases to upgrade, no dependencies to bump, and no API surface that can break. Your upgrade cost is the cost of re-reading: if Oversecured adds findings, you re-open the repository and diff the numbered directories.

The licence is BSD-2-Clause. That is a permissive licence, and for a documentation repository it mostly governs copying and redistribution of the text and any accompanying files. It does not grant rights to Samsung's code, and it does not change the fact that the vulnerability details are public disclosures. If you plan to republish entries or fold them into internal training material, read the licence text in the repository rather than assuming; this is not legal advice.

The real maintenance question is editorial, not technical: an archive that stops receiving entries slowly becomes a historical document. That is fine for training and pattern recognition, and useless for tracking whether a device you hold today is patched.

Editorial conclusion

Adopt this repository as a reading archive if you build or audit Android system apps and want a catalogue of real bug classes: intent redirection, arbitrary content provider access, token leakage, file overwrite with system privilege. Do not adopt it if you need a scanner, a patch, or per-device status, because the repository ships prose and no tooling, and the README states all listed vulnerabilities are already fixed with Oversecured's help. Before relying on any entry, verify the fix against Samsung's own security bulletin for the matching patch level, since the repository does not map entries to build numbers or patch dates.

Frequently asked questions

What are the current security issues with Samsung phones according to the Samsung_Vulnerabilities repository?

The repository does not describe current issues. The README states that all of the 176 vulnerabilities it lists are already fixed with Oversecured's help, and the entries cover reports and fixes from 2022 to 2025.

Does the Samsung_Vulnerabilities repository contain a scanner or tool to check my device?

No. It is a disclosure report made of numbered directories and write-ups, with no build instructions, package name, or command to run. The README mentions Oversecured's scanner as the tool that found the issues, but the scanner is not part of this repository.

Which Samsung apps appear in the Samsung_Vulnerabilities list?

The list spans preinstalled apps including Settings, Galaxy Store, Galaxy Themes Service, SmartThings, Samsung Cloud, Samsung Pay, Samsung Internet Browser, Quick Share, Knox VPN Services, DeX, Bixby Vision, and others. The README table names the affected app for every entry.

Is the Samsung_Vulnerabilities repository still updated?

It is not archived, and the last push was on 2026-07-15. There are no releases, which is expected for a repository whose contents are documentation rather than software.

Official sources

  1. Issues
  2. License: BSD-2-Clause
  3. oversecured/Samsung_Vulnerabilities on GitHub
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/oversecured-samsung-vulnerabilities.svg)](https://hysenlabs.com/projects/oversecured-samsung-vulnerabilities)