whatisgithub

What is samsung_vulnerabilities?

oversecured/samsung_vulnerabilities — explained in plain English

Analysis updated 2026-05-18

293JavaAudience · researcherComplexity · 1/5

In one sentence

A public disclosure report detailing 176 security vulnerabilities that Oversecured found and helped Samsung fix in its preinstalled Android apps between 2022 and 2025.

Mindmap

mindmap
  root((Samsung vulnerabilities))
    What it does
      Documents 176 fixed flaws
      Lists affected apps
      Links detailed writeups
    Tech stack
      Java
      Android apps
    Use cases
      Study fixed vulnerabilities
      Learn disclosure process
      Reference bug bounty rewards
    Audience
      Security researchers
      Android developers
    Notes
      All issues already fixed
      Reference document not a tool
      Reward total over 160000 dollars

Code map

Detail Auto

An interactive map of this repo's files and how they connect — its source is parsed live in your browser. Click Visualize to build it.

filefunction / class

What do people build with it?

USE CASE 1

Study real-world examples of Android app vulnerabilities and how they were fixed

USE CASE 2

Reference how a mobile security firm documents and discloses findings to a vendor

USE CASE 3

Learn what kinds of flaws commonly appear in preinstalled Android system apps

USE CASE 4

See how bug bounty rewards are structured for a vulnerability disclosure program

What is it built with?

JavaAndroid

How does it compare?

oversecured/samsung_vulnerabilitiesszili1994/create-aeronautics-minecraft-modfacebookresearch/asynchronousratchetingtree
Stars293292272
LanguageJavaJavaJava
Last pushed2021-08-31
MaintenanceDormant
Setup difficultymoderatehard
Complexity1/52/55/5
Audienceresearchergeneralresearcher

Figures from each repo's GitHub metadata at analysis time.

So what is it?

This repository is a public disclosure report from Oversecured, a company that specializes in finding security flaws in Android and iOS apps. It documents 176 vulnerabilities the company found in apps that come preinstalled on Samsung phones between 2022 and 2025, all of which have already been reported to and fixed by Samsung. The report explains that Samsung runs its own vulnerability disclosure program and pays researchers who find and report security issues. Oversecured had previously done a smaller two-week study of Samsung's system apps in 2021 that turned up 17 issues, and this longer effort found many more. According to the report, Samsung paid Oversecured over one hundred and sixty thousand dollars in total rewards across this research and ranked the company first on Samsung's own list of top security researchers. The bulk of the repository is a large table listing each vulnerability by number, the name of the affected Samsung app, a short description of the problem, and the dollar reward paid for it. Examples include apps that could be tricked into installing or uninstalling other apps without permission, apps that leaked contact information or authentication tokens, and apps that allowed reading or overwriting files they should not have had access to. Each row links to a folder with a more detailed writeup of that specific issue. This repository is not a tool to install or run. It is a reference document aimed at security researchers, Android developers, and anyone curious about how vulnerabilities are found and reported in real-world mobile apps, and it is written to give credit for and technical detail on already-fixed issues rather than to expose an active risk. The full README is longer than what was shown.

Copy-paste prompts

Prompt 1
Summarize the most serious vulnerability types found in this Samsung disclosure report
Prompt 2
Explain what an intent redirection vulnerability is using an example from this report
Prompt 3
What categories of Samsung apps had the most vulnerabilities reported here
Prompt 4
Help me understand how this vulnerability disclosure process typically works

Frequently asked questions

What is samsung_vulnerabilities?

A public disclosure report detailing 176 security vulnerabilities that Oversecured found and helped Samsung fix in its preinstalled Android apps between 2022 and 2025.

What language is samsung_vulnerabilities written in?

Mainly Java. The stack also includes Java, Android.

Who is samsung_vulnerabilities for?

Mainly researcher.

Open on GitHub → Ask about another repo

This repo across BitVibe Labs

Verify against the repo before relying on details.