Junglewise Threat Intelligence

CVE-2026-21045: Samsung Mobile out-of-bounds write in libimagecodec TIFF parsing

CVE-2026-21045 · Severity: info · CVSS 8.3 · Published 2026-07-10

Vendors: Samsung.

Executive brief

A vulnerability exists in the image processing component of Samsung mobile devices running Android 14, 15, and 16. This component is responsible for handling TIFF image files, and a flaw in how it reads these files could allow a remote attacker to interfere with the device's memory. If exploited, this could lead to unauthorized data modification or system instability, potentially compromising the integrity of the device.

Technical details

An out-of-bounds write vulnerability exists in the TIFF parsing logic of the 'libimagecodec.media.quram.so' library. The flaw is triggered when the library processes a specially crafted TIFF image, leading to memory corruption. A remote attacker can exploit this without user interaction or special privileges, though the CVSS 4.0 vector suggests some technical preconditions (AT:P) may apply. Successful exploitation allows for out-of-bounds memory writes, which can lead to arbitrary code execution or a denial-of-service condition. The issue is addressed in the Samsung SMR Jul-2026 Release 1 for Android versions 14, 15, and 16.

Affected products

  • Samsung Mobile Devices (Android 14, 15, 16) Prior to SMR Jul-2026 Release 1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory
  • 2026-07-01: patched: Addressed in SMR Jul-2026 Release 1

References