Executive brief
The Samsung Android USB Driver for Windows is a software component that allows Windows computers to communicate with Samsung mobile devices. A vulnerability in this driver could allow a local attacker to access restricted memory areas on the computer. This could lead to system instability or unauthorized access to information on the host machine.
Technical details
An out-of-bounds memory access vulnerability exists in the Samsung Android USB Driver for Windows due to improper input validation. A local attacker can exploit this flaw to read or write to memory locations outside of the intended buffer. The vulnerability is present in versions prior to 1.9.5.0. Successful exploitation could lead to a denial of service (system crash) or potentially limited information disclosure. Samsung has addressed this issue in version 1.9.5.0 by implementing proper input validation checks.
Affected products
- Samsung Android USB Driver for Windows prior to 1.9.5.0
Timeline
- 2026-06-02: advisory: Samsung published the security bulletin.
- 2026-06-05: disclosed: CVE published in the NVD dataset.