Junglewise Threat Intelligence

CVE-2026-21088: Samsung libsubextractor improper input validation in subtitle frame loading

CVE-2026-21088 · Severity: high · CVSS 7.8 · Published 2026-09-09

Vendors: Samsung.

Executive brief

libsubextractor.so is a library used by Samsung mobile devices to process subtitle files. A local attacker can exploit improper input validation in subtitle frame loading to write out-of-bounds memory, potentially leading to privilege escalation or denial of service on affected devices.

Technical details

An improper input validation vulnerability exists in libsubextractor.so when loading subtitle frames. The vulnerability allows a local attacker to write out-of-bounds memory by providing specially crafted subtitle data. The vulnerability requires local access to the affected device and the ability to provide malicious subtitle files for processing. An attacker exploiting this flaw could achieve memory corruption, potentially leading to code execution, privilege escalation, or denial of service. The fix is available in Samsung Mobile Security (SMR) September 2026 Release 1 and later.

Affected products

  • Samsung libsubextractor.so prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed
  • 2026-09: patched: Fixed in SMR Sep-2026 Release 1

References