Junglewise Threat Intelligence

CVE-2026-33956: Samsung Exynos mobile processor out-of-bounds write in camera driver

CVE-2026-33956 · Severity: low · CVSS 2.8 · Published 2026-09-14

Technologies: Samsung Exynos 1480, Samsung Exynos 1380, Samsung Exynos 2400, Samsung Exynos 1330, Samsung Exynos 2500, Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung's Exynos mobile processors (used in phones and tablets) contain a vulnerability in the camera driver that can be exploited by sending a malformed message. An attacker can trigger an out-of-bounds memory write that causes the device to become unresponsive or crash, disrupting user access to their device.

Technical details

The vulnerability is an out-of-bounds write (buffer overflow) in the camera driver of Samsung's Exynos mobile processors. The flaw is triggered by sending a malformed message to the test_msg sysfs entry, which fails to properly validate input length before writing to memory. This results in memory corruption that can cause denial of service by crashing the camera subsystem or potentially the entire device. The vulnerability is exploitable without authentication and requires only network access to the affected device. Patch availability is not explicitly confirmed in the available advisory content.

Affected products

  • Samsung Exynos 1330 unknown
  • Samsung Exynos 1380 unknown
  • Samsung Exynos 1480 unknown
  • Samsung Exynos 2400 unknown
  • Samsung Exynos 1580 unknown
  • Samsung Exynos 2500 unknown

Timeline

  • 2026-09-14: disclosed
  • 2025-12-02: reported

References

Related threats