Executive brief
Samsung's Exynos mobile processors (used in phones and tablets) contain a vulnerability in the camera driver that can be exploited by sending a malformed message. An attacker can trigger an out-of-bounds memory write that causes the device to become unresponsive or crash, disrupting user access to their device.
Technical details
The vulnerability is an out-of-bounds write (buffer overflow) in the camera driver of Samsung's Exynos mobile processors. The flaw is triggered by sending a malformed message to the test_msg sysfs entry, which fails to properly validate input length before writing to memory. This results in memory corruption that can cause denial of service by crashing the camera subsystem or potentially the entire device. The vulnerability is exploitable without authentication and requires only network access to the affected device. Patch availability is not explicitly confirmed in the available advisory content.
Affected products
- Samsung Exynos 1330 unknown
- Samsung Exynos 1380 unknown
- Samsung Exynos 1480 unknown
- Samsung Exynos 2400 unknown
- Samsung Exynos 1580 unknown
- Samsung Exynos 2500 unknown
Timeline
- 2026-09-14: disclosed
- 2025-12-02: reported