Executive brief
Samsung Exynos mobile processors contain a vulnerability in their Wi-Fi component that processes network configuration commands. A specially crafted network command can trigger an out-of-bounds memory read, potentially exposing sensitive information from device memory. This could allow an attacker with local network access to leak confidential data.
Technical details
A malformed Netlink command can trigger an out-of-bounds read in the Wi-Fi subsystem of Samsung Exynos processors. The vulnerability exists in the Wi-Fi component's Netlink command processing logic, where insufficient bounds checking on incoming network configuration commands allows reading beyond allocated memory regions. This is a local information disclosure vulnerability requiring some level of access to the Netlink interface. An attacker can leak sensitive kernel or driver memory contents, potentially revealing cryptographic keys, addresses for further exploitation, or other confidential data. Patches are available from Samsung semiconductor.
Affected products
- Samsung Exynos 850 unspecified
- Samsung Exynos 1280 unspecified
- Samsung Exynos 1330 unspecified
- Samsung Exynos 1380 unspecified
- Samsung Exynos 1480 unspecified
- Samsung Exynos 2400 unspecified
- Samsung Exynos W920 unspecified
- Samsung Exynos W930 unspecified
Timeline
- 2026-09-14: disclosed: CVE-2026-33962 published
- 2026-02-02: advisory: Vulnerability reported to Samsung