Executive brief
Samsung's libimagecodec library, used by mobile devices to decode JPEG images, contains a heap-based buffer overflow vulnerability. An attacker can send a specially crafted JPEG file to a device to trigger the vulnerability and execute arbitrary code, potentially gaining full control of the device and accessing sensitive user data.
Technical details
A heap-based buffer overflow exists in the JPEG decoder component of libimagecodec.quram.so, a Samsung system library used across their mobile platforms. The vulnerability is triggered when processing malformed JPEG image data, allowing an attacker to write beyond allocated heap memory boundaries. The flaw requires only network access to deliver a malicious JPEG file (no authentication needed), and successful exploitation results in arbitrary code execution with the privileges of the process decoding the image. The vulnerability was patched in Samsung's September 2026 security update (SMR Sep-2026 Release 1).
Affected products
- Samsung libimagecodec prior to SMR Sep-2026 Release 1
Timeline
- 2026-09-09: disclosed
- 2026-09: patched