Junglewise Threat Intelligence

CVE-2026-21049: Samsung Mobile out-of-bounds write in libpadm.so

CVE-2026-21049 · Severity: info · CVSS 8.4 · Published 2026-07-10

Executive brief

A security vulnerability exists in a system library used by Samsung mobile devices running Android 14, 15, and 16. A malicious application installed on the device could exploit this flaw to gain unauthorized control and execute its own code. This could lead to the compromise of personal data or the disruption of device operations.

Technical details

An out-of-bounds write vulnerability exists in the libpadm.so library within Samsung's Android implementation. The flaw is triggered when the library improperly handles memory boundaries during write operations. A local attacker with low privileges (e.g., a malicious app) can exploit this to overwrite memory and achieve arbitrary code execution with the privileges of the affected process. The vulnerability affects devices running Android 14, 15, and 16 prior to the July 2026 Security Maintenance Release (SMR). Samsung has addressed this issue in the SMR Jul-2026 Release 1.

Affected products

  • Samsung Mobile Samsung Mobile Devices (Android 14, 15, 16) Prior to SMR Jul-2026 Release 1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory
  • 2026-07-01: patched: Addressed in SMR Jul-2026 Release 1

References