Junglewise Threat Intelligence

CVE-2026-33962: Samsung Exynos out-of-bounds read in Wi-Fi Netlink processing

CVE-2026-33962 · Severity: low · CVSS 2.8 · Published 2026-09-14

Technologies: Samsung Exynos 1280, Samsung Exynos 1480, Samsung Exynos 1380, Samsung Exynos W930, Samsung Exynos W920, Samsung Exynos 2400, Samsung Exynos 1330, Samsung Exynos 850. Vendors: Samsung.

Executive brief

Samsung Exynos mobile processors contain a vulnerability in their Wi-Fi component that processes network configuration commands. A specially crafted network command can trigger an out-of-bounds memory read, potentially exposing sensitive information from device memory. This could allow an attacker with local network access to leak confidential data.

Technical details

A malformed Netlink command can trigger an out-of-bounds read in the Wi-Fi subsystem of Samsung Exynos processors. The vulnerability exists in the Wi-Fi component's Netlink command processing logic, where insufficient bounds checking on incoming network configuration commands allows reading beyond allocated memory regions. This is a local information disclosure vulnerability requiring some level of access to the Netlink interface. An attacker can leak sensitive kernel or driver memory contents, potentially revealing cryptographic keys, addresses for further exploitation, or other confidential data. Patches are available from Samsung semiconductor.

Affected products

  • Samsung Exynos 850 unspecified
  • Samsung Exynos 1280 unspecified
  • Samsung Exynos 1330 unspecified
  • Samsung Exynos 1380 unspecified
  • Samsung Exynos 1480 unspecified
  • Samsung Exynos 2400 unspecified
  • Samsung Exynos W920 unspecified
  • Samsung Exynos W930 unspecified

Timeline

  • 2026-09-14: disclosed: CVE-2026-33962 published
  • 2026-02-02: advisory: Vulnerability reported to Samsung

References

Related threats