Executive brief
Samsung's image codec library (libimagecodec.quram.so) contains a critical vulnerability in its DNG (Digital Negative) image format decoder. An attacker can exploit this flaw by sending a specially crafted DNG image file to a device, potentially executing arbitrary code and gaining full control over the device. This could lead to data theft, malware installation, and complete compromise of the affected mobile device.
Technical details
A heap-based buffer overflow exists in the DNG image decoder component of Samsung's libimagecodec.quram.so library. The vulnerability is triggered when processing malformed or oversized DNG image data, causing a buffer overrun that can corrupt heap memory. An attacker can deliver the malicious image via network, email attachment, or web browsing without requiring user authentication. Successful exploitation allows remote code execution with the privileges of the process handling image decoding. Samsung released a patch as part of the SMR (Security Maintenance Release) September 2026 Release 1 update.
Affected products
- Samsung libimagecodec prior to SMR Sep-2026 Release 1
Timeline
- 2026-09-09: disclosed: CVE-2026-21095 published on NVD
- 2026-09: patched: Fix included in Samsung SMR Sep-2026 Release 1