Executive brief
Samsung Escargot, an open-source JavaScript engine often used in smart TVs and appliances, contains a security flaw that could lead to information disclosure. An attacker could exploit this vulnerability to read sensitive data from the system's memory that should otherwise be protected. This could result in the exposure of internal system resources or private user information, potentially impacting the privacy and security of the device.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Samsung's Escargot JavaScript engine. The flaw is located within the engine's handling of memory buffers, where insufficient bounds checking allows a read operation to exceed the intended buffer limits. A remote attacker can exploit this by providing specially crafted JavaScript code that triggers the out-of-bounds access. Successful exploitation can lead to the exposure of sensitive memory contents (resource leak) or a partial denial of service. The vulnerability was addressed in pull request #1554 on the Escargot GitHub repository.
Affected products
- Samsung Escargot 97e8115ab1110bc502b4b5e4a0c689a71520d335
Timeline
- 2026-04-13: advisory: Initial disclosure by Samsung TV & Appliance
- 2026-04-08: patched: Fix merged in GitHub pull request #1554
- 2026-04-28: other: NVD analysis and enrichment completed