Junglewise Threat Intelligence

CVE-2026-10305: Samsung rlottie out-of-bounds read in animation rendering

CVE-2026-10305 · Severity: medium · CVSS 6.1 · Published 2026-06-04

Technologies: Samsung Rlottie. Vendors: Samsung.

Executive brief

Samsung rlottie is an open-source library used for rendering vector-based animations. A vulnerability in this library could allow a specially crafted animation file to cause a crash or unexpected behavior when processed. This could lead to service disruptions or application instability on devices that use this library to display animations, such as smart TVs or mobile apps.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Samsung's rlottie library due to an overread buffer issue, specifically related to a signed shift error in the code. The vulnerability is triggered when the library processes a malformed animation file. An attacker can exploit this by enticing a user to open a malicious file (User Interaction required), leading to a denial-of-service (application crash) or potentially limited information disclosure. The issue is local in nature (AV:L) and has been addressed in commit 223a2a41ba4f462e4abe767bebba49a366c9b9fd.

Affected products

  • Samsung rlottie before 223a2a41ba4f462e4abe767bebba49a366c9b9fd

Timeline

  • 2026-05-12: patched: Fix merged into master branch via pull request 587
  • 2026-06-04: disclosed: CVE published by Samsung TV & Appliance

References

Related threats