Junglewise Threat Intelligence

CVE-2026-21047: Samsung Mobile ImsService out-of-bounds write

CVE-2026-21047 · Severity: info · CVSS 8.3 · Published 2026-07-28

Vendors: Samsung.

Executive brief

A vulnerability exists in the IP Multimedia Subsystem (IMS) service on Samsung mobile devices, which handles multimedia communications like Voice over LTE (VoLTE) and Wi-Fi calling. A remote attacker could exploit this flaw to potentially execute unauthorized code on the device. This could lead to a total loss of device integrity and availability, potentially allowing an attacker to disrupt operations or gain control over the handset.

Technical details

An out-of-bounds (OOB) write vulnerability exists in the Samsung ImsService component. The flaw is reachable over the network without requiring prior authentication or user interaction, though the CVSS vector suggests specific attack requirements (AT:P) may be necessary. A successful exploit allows a remote attacker to write data outside of intended memory buffers, potentially leading to arbitrary code execution (ACE) on the affected Android device. The vulnerability is addressed in the Samsung SMR Jul-2026 Release 1 for devices running Android 14, 15, and 16.

Affected products

  • Samsung Mobile Devices (Android 14, 15, 16) Prior to SMR Jul-2026 Release 1

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-01: patched: Addressed in SMR Jul-2026 Release 1

References