Executive brief
Samsung Mobile's libsmsd library, a core system component used in mobile devices, contains an input validation flaw that allows local attackers to write data outside intended memory boundaries. A successful exploit could lead to device instability, data corruption, or code execution, requiring an attacker with local access to the device.
Technical details
The vulnerability is an improper input validation flaw in libsmsd.so affecting Samsung Mobile Security releases prior to the Aug-2026 Release 1. The issue allows an attacker with local access to the device to trigger an out-of-bounds memory write, a classic memory safety violation. Attack requires local code execution on the target device. The flaw was patched in the August 2026 security update. CVSS score of 7.8 reflects the high impact potential combined with the local access requirement.
Affected products
- Samsung Mobile Security prior to Aug-2026 Release 1
Timeline
- 2026-08-10: advisory