Executive brief
Samsung's Exynos mobile processors (used in Galaxy smartphones and tablets) contain a camera driver vulnerability that can corrupt kernel memory when exploited. An attacker with local device access could leverage this to crash the system, escalate privileges, or potentially execute arbitrary code, affecting the stability and security of affected mobile devices.
Technical details
An out-of-bounds memory access vulnerability exists in the camera GDC (Geometric Distortion Correction) driver on Samsung Exynos processors 1330, 1380, 1480, and 2400. The vulnerability arises from improper bounds checking in the driver, allowing an attacker to read or write memory outside allocated buffers. Exploitation requires local access to the device and likely interaction with or control over camera operations. Successful exploitation can lead to kernel memory corruption, system crashes, or privilege escalation. Samsung has classified this as medium severity and patches should be available through device security updates.
Affected products
- Samsung Exynos 1330 All affected versions
- Samsung Exynos 1380 All affected versions
- Samsung Exynos 1480 All affected versions
- Samsung Exynos 2400 All affected versions
Timeline
- 2026-09-14: disclosed