Executive brief
DualDAR is a Samsung security component used in mobile devices. A use-after-free memory vulnerability allows a locally authenticated privileged attacker to execute arbitrary code with root-level access, potentially compromising the entire device and any data stored on it.
Technical details
A use-after-free vulnerability exists in Samsung DualDAR prior to the SMR Sep-2026 Release 1 patch. The flaw allows a local attacker with elevated privileges to trigger memory corruption by accessing freed memory, enabling arbitrary code execution with root privilege. The vulnerability requires local access and elevated privileges as a precondition. The patch is available in the September 2026 security update (SMR Sep-2026 Release 1).
Affected products
- Samsung DualDAR prior to SMR Sep-2026 Release 1
Timeline
- 2026-09-09: disclosed