Executive brief
Samsung Escargot, an open-source JavaScript engine often used in smart TVs and appliances, contains a security vulnerability that could allow an attacker to crash the system or potentially execute unauthorized code. This occurs due to a mathematical error when processing data, which can lead to memory corruption. If exploited, this could impact the stability of the device or the privacy of user data handled by the engine.
Technical details
An integer overflow vulnerability (CWE-190) exists in Samsung's Escargot JavaScript engine. The flaw occurs when the engine improperly handles arithmetic operations, leading to a buffer overflow condition. An attacker can exploit this over a network without authentication, though the attack complexity is rated as high, likely requiring specific environmental conditions or complex payloads to achieve reliable memory corruption. Successful exploitation could grant the attacker the ability to execute arbitrary code or cause a crash (denial of service). A fix has been identified in the project's repository via pull request #1554.
Affected products
- Samsung Escargot 97e8115ab1110bc502b4b5e4a0c689a71520d335
Timeline
- 2026-04-08: patched: Fix merged in GitHub pull request 1554
- 2026-04-13: advisory: CVE published by Samsung TV & Appliance
- 2026-04-28: other: NVD initial analysis completed