oversecured/samsung_vulnerabilities — explained in plain English
Analysis updated 2026-05-18
Study real-world examples of Android app vulnerabilities and how they were fixed
Reference how a mobile security firm documents and discloses findings to a vendor
Learn what kinds of flaws commonly appear in preinstalled Android system apps
See how bug bounty rewards are structured for a vulnerability disclosure program
| oversecured/samsung_vulnerabilities | szili1994/create-aeronautics-minecraft-mod | facebookresearch/asynchronousratchetingtree | |
|---|---|---|---|
| Stars | 293 | 292 | 272 |
| Language | Java | Java | Java |
| Last pushed | — | — | 2021-08-31 |
| Maintenance | — | — | Dormant |
| Setup difficulty | — | moderate | hard |
| Complexity | 1/5 | 2/5 | 5/5 |
| Audience | researcher | general | researcher |
Figures from each repo's GitHub metadata at analysis time.
This repository is a public disclosure report from Oversecured, a company that specializes in finding security flaws in Android and iOS apps. It documents 176 vulnerabilities the company found in apps that come preinstalled on Samsung phones between 2022 and 2025, all of which have already been reported to and fixed by Samsung. The report explains that Samsung runs its own vulnerability disclosure program and pays researchers who find and report security issues. Oversecured had previously done a smaller two-week study of Samsung's system apps in 2021 that turned up 17 issues, and this longer effort found many more. According to the report, Samsung paid Oversecured over one hundred and sixty thousand dollars in total rewards across this research and ranked the company first on Samsung's own list of top security researchers. The bulk of the repository is a large table listing each vulnerability by number, the name of the affected Samsung app, a short description of the problem, and the dollar reward paid for it. Examples include apps that could be tricked into installing or uninstalling other apps without permission, apps that leaked contact information or authentication tokens, and apps that allowed reading or overwriting files they should not have had access to. Each row links to a folder with a more detailed writeup of that specific issue. This repository is not a tool to install or run. It is a reference document aimed at security researchers, Android developers, and anyone curious about how vulnerabilities are found and reported in real-world mobile apps, and it is written to give credit for and technical detail on already-fixed issues rather than to expose an active risk. The full README is longer than what was shown.
A public disclosure report detailing 176 security vulnerabilities that Oversecured found and helped Samsung fix in its preinstalled Android apps between 2022 and 2025.
Mainly Java. The stack also includes Java, Android.
Mainly researcher.
This repo across BitVibe Labs
Don't trust strangers blindly. Verify against the repo.