Junglewise Threat Intelligence

CVE-2026-21110: Samsung One UI out-of-bounds write in libsavscmn.so

CVE-2026-21110 · Severity: info · Published 2026-09-09

Technologies: Samsung One UI. Vendors: Samsung.

Executive brief

Samsung One UI, the operating system that runs Samsung mobile devices, contains a vulnerable shared library (libsavscmn.so) that can be exploited by local attackers to execute arbitrary code. A local attacker with access to the device can trigger an out-of-bounds write condition to gain full control of the system, potentially compromising all data and functionality on the device.

Technical details

This vulnerability is an out-of-bounds write flaw in libsavscmn.so, a shared library component in Samsung One UI prior to version 8.5. The root cause appears to be insufficient input validation or buffer boundary checking in the vulnerable component. The attack requires local access to the device; a local attacker can craft specific input to trigger the out-of-bounds write, potentially achieving arbitrary code execution with the privileges of the affected process. The fix is available in One UI 8.5 and later versions, which adds proper input validation to prevent the out-of-bounds write condition.

Affected products

  • Samsung One UI prior to 8.5

Timeline

  • 2026-09-09: disclosed

References

Related threats