Junglewise Threat Intelligence

CVE-2026-21066: Samsung libcodec2_sec_flacdec out-of-bounds write

CVE-2026-21066 · Severity: high · CVSS 7.8 · Published 2026-08-10

Technologies: Samsung Mobile Firmware. Vendors: Samsung.

Executive brief

A vulnerability in Samsung's FLAC audio decoding library (libcodec2_sec_flacdec.so) allows local attackers to write to memory locations outside the intended bounds. This could enable an attacker with local access to corrupt system memory, crash services, or potentially gain elevated privileges. The vulnerability was patched in Samsung's August 2026 security release.

Technical details

The vulnerability stems from improper input validation in libcodec2_sec_flacdec.so, a FLAC audio decoder library used in Samsung firmware. An attacker with local access can craft malicious FLAC audio input that bypasses bounds checking, leading to an out-of-bounds write condition. This allows arbitrary memory corruption within the decoder process, potentially enabling privilege escalation, denial of service, or arbitrary code execution depending on process privileges and memory layout. The fix is available in Samsung Mobile's August 2026 Release 1 security update.

Affected products

  • Samsung Mobile Firmware prior to SMR Aug-2026 Release 1

Timeline

  • 2026-08-10: disclosed
  • 2026-08: patched: SMR Aug-2026 Release 1

References

Related threats