Junglewise Threat Intelligence

CVE-2026-33957: Samsung Exynos 1580 CustOS Driver out-of-bounds memory access

CVE-2026-33957 · Severity: medium · CVSS 4.2 · Published 2026-09-14

Technologies: Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung's Exynos 1580 mobile processor contains a vulnerability in its CustOS (Customizable Trusted OS) driver that allows an attacker to request oversized shared memory allocations. This flaw can result in out-of-bounds memory reads and writes, potentially corrupting sensitive data, leaking information from the device, or causing system instability. Devices using this processor may be exposed to privilege escalation or information disclosure attacks.

Technical details

The vulnerability is an out-of-bounds memory access flaw in the CustOS Driver component of Samsung's Exynos 1580 processor. The root cause is insufficient bounds checking when handling oversized shared memory requests to the custos_iwc (Inter-world Communication) device interface. An attacker with local or firmware-level access can craft requests that exceed the allocated buffer size, enabling out-of-bounds reads and writes to kernel or trusted execution environment (TEE) memory. This can lead to memory corruption, information leakage, or privilege escalation. Patch availability from Samsung is not explicitly confirmed in the provided advisory.

Affected products

  • Samsung Exynos 1580 <UNKNOWN>

Timeline

  • 2026-09-14: disclosed: CVE-2026-33957 published on NVD
  • 2026-01-07: other: Reported date per Samsung security advisory

References

Related threats