Junglewise Threat Intelligence

CVE-2026-21087: Samsung libmdnie Out-of-bounds write privilege escalation

CVE-2026-21087 · Severity: high · CVSS 7.8 · Published 2026-09-09

Vendors: Samsung.

Executive brief

A memory safety vulnerability in Samsung's libmdnie display management library allows local attackers to write data outside of allocated memory, leading to arbitrary code execution with system-level privileges. This affects Samsung mobile devices and could allow a malicious app or compromised process to gain control of core system functions.

Technical details

The vulnerability is an out-of-bounds write in libmdnie.so, a Samsung library responsible for display and mobile display-related functionality. Local attackers can trigger the vulnerability to write to memory outside intended bounds, leading to code execution in the system server process context. The attack requires local access to the device but does not require authentication or user interaction beyond initial installation. The vulnerability was patched in Samsung Mobile Release (SMR) September 2026 Release 1 and later.

Affected products

  • Samsung Galaxy Mobile Devices prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed

References