Executive brief
A memory writing vulnerability exists in Samsung's codec library used in mobile devices. A local attacker can exploit this to write data beyond intended memory boundaries, potentially corrupting system memory, crashing the device, or executing malicious code with elevated privileges.
Technical details
The vulnerability is an out-of-bounds write flaw in libcodec2secevrcdec.so, a component of Samsung's codec processing library. The vulnerability requires local access to the affected system and can be triggered to write arbitrary data beyond allocated memory boundaries. Successful exploitation may lead to memory corruption, denial of service, or potential privilege escalation depending on the memory context and attack sophistication. The issue was patched in Samsung Mobile's SMR September 2026 Release 1 security update.
Affected products
- Samsung Android firmware Prior to SMR September 2026 Release 1
Timeline
- 2026-09-09: disclosed
- 2026-09: patched: Samsung Mobile SMR September 2026 Release 1