Junglewise Threat Intelligence

CVE-2026-21089: Samsung libsubextractor out-of-bounds write in style tag parsing

CVE-2026-21089 · Severity: high · CVSS 7.8 · Published 2026-09-09

Technologies: Samsung One UI. Vendors: Samsung.

Executive brief

A library used by Samsung devices to extract and parse subtitle content contains a flaw in how it validates input when removing style tags. A local attacker could exploit this to write data outside the intended memory boundaries, potentially crashing the application or executing arbitrary code with the privileges of the process handling the subtitle data.

Technical details

The vulnerability is an out-of-bounds write (improper input validation / buffer overflow) in libsubextractor.so, a Samsung library responsible for subtitle extraction and formatting. The flaw occurs in the style tag removal logic when processing malformed or specially crafted subtitle input. An attacker with local access can provide a crafted subtitle file to trigger the out-of-bounds write, enabling memory corruption that could lead to denial of service or code execution. The vulnerability affects versions prior to the September 2026 SMR (Security Maintenance Release) 1 patch. No active exploitation in the wild is currently documented.

Affected products

  • Samsung One UI prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed
  • 2026-09: patched: SMR Sep-2026 Release 1

References

Related threats