Junglewise Threat Intelligence

CVE-2026-21018: Samsung SveService out-of-bounds write

CVE-2026-21018 · Severity: medium · CVSS 6.7 · Published 2026-05-13

Vendors: Samsung.

Executive brief

A security vulnerability exists in Samsung's SveService, a component used in Samsung mobile devices. A local attacker with high-level privileges could exploit this flaw to run unauthorized code on the device. This could lead to a complete compromise of the device's integrity and the exposure of sensitive user data.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the SveService component of Samsung Android devices. The flaw is present in versions prior to the SMR May-2026 Release 1. An attacker with local access and high privileges (PR:H) can exploit this memory corruption issue to execute arbitrary code with the permissions of the service. The vulnerability is addressed in the Samsung Security Maintenance Release (SMR) for May 2026.

Affected products

  • Samsung Android Prior to SMR May-2026 Release 1

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References