Executive brief
Samsung's Exynos mobile and wearable processors contain a flaw in the Wi-Fi interface driver that can be exploited by sending malformed commands. This vulnerability allows an attacker to trigger improper memory allocation and write beyond buffer boundaries, causing the device to become unresponsive or crash. Affected devices include a range of Samsung mobile phones and smartwatches using these processors.
Technical details
The vulnerability exists in the Wi-Fi interface driver of Samsung Exynos processors (both mobile and wearable variants). A malformed ioctl command sent to the Wi-Fi device driver causes improper buffer size allocation, leading to an out-of-bounds write condition. This memory corruption can result in denial of service (DoS) by causing the driver or kernel to crash. The attack vector is local and likely requires elevated privileges or specific driver access. Samsung has acknowledged the issue; patch status and availability details are not provided in the advisory.
Affected products
- Samsung Exynos 1330 Not specified
- Samsung Exynos 1380 Not specified
- Samsung Exynos 1480 Not specified
- Samsung Exynos 1580 Not specified
- Samsung Exynos 1680 Not specified
- Samsung Exynos W920 Not specified
- Samsung Exynos W930 Not specified
- Samsung Exynos W1000 Not specified
Timeline
- 2026-09-14: disclosed: CVE-2026-33960 publicly disclosed
- 2025-12-18: other: Vulnerability reported to Samsung