Junglewise Threat Intelligence

CVE-2026-21071: Samsung libsavsvc improper input validation in MPEG4 codec

CVE-2026-21071 · Severity: high · CVSS 7.8 · Published 2026-08-10

Vendors: Samsung.

Executive brief

A memory corruption vulnerability exists in Samsung's MPEG4 video codec library (libsavsvc.so) used in mobile devices. Local attackers can exploit improper input validation to write data outside of allocated memory boundaries, potentially leading to device crashes, privilege escalation, or code execution. The vulnerability requires local access to the affected device.

Technical details

The vulnerability is an improper input validation flaw in the MPEG4 codec implementation within libsavsvc.so. It allows out-of-bounds memory writes when processing specially crafted MPEG4 media files. The attack vector is local—an attacker must have access to execute code or provide malicious media files on the device. The vulnerable component is part of Samsung's media processing stack. Patches are available in the SMR (Samsung Mobile Release) August 2026 Release 1 and later versions. The vulnerability enables memory corruption that could be chained with other exploits for privilege escalation or code execution.

Affected products

  • Samsung Android firmware (libsavsvc.so MPEG4 codec) prior to SMR Aug-2026 Release 1

Timeline

  • 2026-08-10: disclosed
  • 2026-08: patched: Patch available in SMR Aug-2026 Release 1

References