Executive brief
Samsung Escargot, an open-source JavaScript engine often used in smart TVs and appliances, contains a security flaw that could lead to information disclosure. An attacker could exploit this vulnerability to read sensitive data from the system's memory that should otherwise be protected. This could result in the leakage of private information or system resources, potentially compromising the privacy and stability of the affected device.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Samsung Open Source Escargot, specifically affecting commit 97e8115ab1110bc502b4b5e4a0c689a71520d335. The flaw occurs when the engine reads data beyond the end of the intended buffer, which can lead to the exposure of sensitive memory contents or 'Resource Leak Exposure.' While the NVD lists a network-based vector with high severity, the vendor (Samsung TV & Appliance) specifies a local attack vector with high complexity. A patch has been identified in the project's GitHub repository under pull request #1554.
Affected products
- Samsung Escargot 97e8115ab1110bc502b4b5e4a0c689a71520d335
Timeline
- 2026-04-08: patched: Fix merged in GitHub pull request 1554
- 2026-04-13: disclosed: Initial disclosure by Samsung TV & Appliance
- 2026-04-13: advisory: CVE-2026-25206 published to NVD