Executive brief
Samsung Mobile's audio codec library (libcodec2secqcelpdec.so) contains a memory safety flaw that allows a local attacker to write data beyond allocated buffer boundaries. This could lead to system crash, privilege escalation, or arbitrary code execution on affected Samsung devices, compromising device integrity and user data.
Technical details
The vulnerability is an out-of-bounds write flaw in libcodec2secqcelpdec.so, a shared library used for audio codec processing in Samsung mobile devices. The defect allows a local attacker to write to memory outside the bounds of an allocated buffer. Attack requires local access to the device; no network vector is present. Successful exploitation could result in denial of service, privilege escalation, or arbitrary code execution with the privileges of the affected codec process. The flaw was patched in Samsung Mobile's SMR August 2026 Release 1.
Affected products
- Samsung Mobile Devices (SMR Aug-2026 Release 1 and earlier)
Timeline
- 2026-08-10: disclosed
- 2026-08: patched: Samsung Mobile SMR August 2026 Release 1