Executive brief
A library component in Samsung's One UI mobile operating system contains a memory corruption flaw that allows local attackers to write data beyond allocated memory boundaries. This could enable device compromise or local privilege escalation by an attacker with physical access or via a compromised application.
Technical details
An out-of-bounds write vulnerability exists in the libsthmbc.so shared library component in Samsung One UI versions prior to 8.5. The vulnerability stems from insufficient input validation, allowing local attackers to write data beyond allocated memory boundaries. Attack requires local code execution (physical device access or compromised application). The vulnerability can result in memory corruption, denial of service, or potential privilege escalation. Samsung released a patch in One UI 8.5 that adds proper input validation to prevent out-of-bounds writes.
Affected products
- Samsung One UI prior to 8.5
Timeline
- 2026-09-09: disclosed