Junglewise Threat Intelligence

CVE-2026-33960: Samsung Exynos processor Wi-Fi driver out-of-bounds write

CVE-2026-33960 · Severity: low · CVSS 2.8 · Published 2026-09-14

Technologies: Samsung Exynos 1480, Samsung Exynos 1380, Samsung Exynos W930, Samsung Exynos W920, Samsung Exynos W1000, Samsung Exynos 1680, Samsung Exynos 1330, Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung's Exynos mobile and wearable processors contain a flaw in the Wi-Fi interface driver that can be exploited by sending malformed commands. This vulnerability allows an attacker to trigger improper memory allocation and write beyond buffer boundaries, causing the device to become unresponsive or crash. Affected devices include a range of Samsung mobile phones and smartwatches using these processors.

Technical details

The vulnerability exists in the Wi-Fi interface driver of Samsung Exynos processors (both mobile and wearable variants). A malformed ioctl command sent to the Wi-Fi device driver causes improper buffer size allocation, leading to an out-of-bounds write condition. This memory corruption can result in denial of service (DoS) by causing the driver or kernel to crash. The attack vector is local and likely requires elevated privileges or specific driver access. Samsung has acknowledged the issue; patch status and availability details are not provided in the advisory.

Affected products

  • Samsung Exynos 1330 Not specified
  • Samsung Exynos 1380 Not specified
  • Samsung Exynos 1480 Not specified
  • Samsung Exynos 1580 Not specified
  • Samsung Exynos 1680 Not specified
  • Samsung Exynos W920 Not specified
  • Samsung Exynos W930 Not specified
  • Samsung Exynos W1000 Not specified

Timeline

  • 2026-09-14: disclosed: CVE-2026-33960 publicly disclosed
  • 2025-12-18: other: Vulnerability reported to Samsung

References

Related threats