Junglewise Threat Intelligence

CVE-2026-21048: Samsung Mobile out-of-bounds write in DNG parsing library

CVE-2026-21048 · Severity: info · CVSS 8.3 · Published 2026-07-10

Vendors: Samsung.

Executive brief

A vulnerability exists in how certain Samsung mobile devices process DNG image files. An attacker could potentially exploit this flaw to corrupt system memory by sending a specially crafted image file. This could lead to unauthorized data modification or system instability on affected Android devices.

Technical details

An out-of-bounds write vulnerability exists in the libimagecodec.media.quram.so library used for parsing DNG (Digital Negative) format images. The flaw is triggered during the parsing process, allowing a remote attacker to achieve an out-of-bounds memory write. The attack vector is over the network with no user interaction or privileges required, though the CVSS vector indicates some technical preconditions (AT:P) may apply. Successful exploitation could lead to memory corruption and potentially arbitrary code execution or a denial-of-service condition. The issue is addressed in the Samsung SMR Jul-2026 Release 1 for devices running Android 14, 15, and 16.

Affected products

  • Samsung Samsung Mobile Devices (Android 14, 15, 16) Prior to SMR Jul-2026 Release 1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory
  • 2026-07-01: patched: SMR Jul-2026 Release 1

References