Executive brief
A security vulnerability exists in a system library used by Samsung mobile devices running Android 14, 15, and 16. A malicious application installed on the device could exploit this flaw to gain unauthorized control and execute its own code. This could lead to a total compromise of the device, allowing an attacker to access sensitive user data or interfere with normal operations.
Technical details
An out-of-bounds write vulnerability exists in the 'libsavsac.so' shared library on Samsung mobile devices. The flaw is triggered when the library improperly handles memory boundaries during write operations. A local attacker with low privileges can exploit this vulnerability to overwrite memory and achieve arbitrary code execution with the permissions of the process using the library. The vulnerability affects Samsung devices running Android versions 14, 15, and 16, and was addressed in the SMR Jul-2026 Release 1 security update.
Affected products
- Samsung Mobile Devices (Android 14, 15, 16) Prior to SMR Jul-2026 Release 1
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory