Junglewise Threat Intelligence

CVE-2026-21090: Samsung libsaviextractor out-of-bounds write

CVE-2026-21090 · Severity: high · CVSS 7.8 · Published 2026-09-09

Vendors: Samsung.

Executive brief

libsaviextractor is a Samsung firmware library responsible for extracting and processing system data. An out-of-bounds write vulnerability allows local attackers with device access to corrupt memory and potentially execute code or crash the system, affecting device integrity and user data security.

Technical details

The vulnerability is an out-of-bounds write in libsaviextractor.so, a component of Samsung's firmware stack. The flaw allows a local attacker to write data beyond allocated memory boundaries, potentially enabling arbitrary code execution or denial of service. Exploitation requires local access to the device. The vulnerability was patched in the Samsung Mobile Security (SMR) September 2026 Release 1 update.

Affected products

  • Samsung Mobile Device Firmware prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed
  • 2026-09: patched: SMR Sep-2026 Release 1

References