Executive brief
Samsung mobile processors include a camera driver component that processes image-related data. A malformed message sent to this driver can cause a memory overflow, leading to service disruption or device crashes. Attackers with local or privileged access could trigger this condition, affecting devices that rely on the Exynos processor for mobile imaging.
Technical details
A stack-based buffer overflow exists in the camera driver component of affected Samsung Exynos processors (1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680). The vulnerability is triggered when a malformed message is processed by the camera driver, causing improper memory handling that results in denial of service or potential code execution. The attack requires the ability to send malicious messages to the camera driver; depending on the device configuration, this may require local access or elevated privileges. Exploitation leads to memory corruption and service disruption. Patches are expected to be available through Samsung firmware updates for affected products.
Affected products
- Samsung Exynos 1330 unspecified
- Samsung Exynos 1380 unspecified
- Samsung Exynos 1480 unspecified
- Samsung Exynos 2400 unspecified
- Samsung Exynos 1580 unspecified
- Samsung Exynos 2500 unspecified
- Samsung Exynos 2600 unspecified
- Samsung Exynos 1680 unspecified
Timeline
- 2026-09-14: disclosed: CVE published on NVD
- 2025-12-29: other: Reported date per Samsung advisory