Junglewise Threat Intelligence

CVE-2026-25207: Samsung Escargot out-of-bounds write

CVE-2026-25207 · Severity: high · CVSS 7.4 · Published 2026-04-13

Technologies: Samsung Escargot. Vendors: Samsung.

Executive brief

Samsung Escargot, an open-source JavaScript engine often used in smart TVs and appliances, contains a memory management flaw. An attacker could exploit this vulnerability to cause system crashes or potentially execute unauthorized code. This could lead to a loss of device stability or the compromise of sensitive data handled by the engine.

Technical details

An out-of-bounds (OOB) write vulnerability exists in Samsung's Escargot JavaScript engine. The flaw is classified as CWE-787 and allows for buffer overflows during memory operations. According to the vendor's CVSS assessment, the attack vector is local with high complexity and requires no prior privileges or user interaction. Successful exploitation can lead to a complete loss of confidentiality, integrity, and availability. A fix appears to have been addressed in pull request #1554 on the project's GitHub repository.

Affected products

  • Samsung Escargot 97e8115ab1110bc502b4b5e4a0c689a71520d335

Timeline

  • 2026-04-13: advisory: Initial disclosure by Samsung TV & Appliance
  • 2026-04-13: disclosed
  • 2026-04-08: patched: Fix merged in GitHub pull request 1554

References

Related threats