Junglewise Threat Intelligence

CVE-2026-33963: Samsung Exynos camera driver stack buffer overflow

CVE-2026-33963 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Samsung Exynos 1480, Samsung Exynos 1380, Samsung Exynos 2600, Samsung Exynos 2400, Samsung Exynos 1680, Samsung Exynos 1330, Samsung Exynos 2500, Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung mobile processors include a camera driver component that processes image-related data. A malformed message sent to this driver can cause a memory overflow, leading to service disruption or device crashes. Attackers with local or privileged access could trigger this condition, affecting devices that rely on the Exynos processor for mobile imaging.

Technical details

A stack-based buffer overflow exists in the camera driver component of affected Samsung Exynos processors (1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680). The vulnerability is triggered when a malformed message is processed by the camera driver, causing improper memory handling that results in denial of service or potential code execution. The attack requires the ability to send malicious messages to the camera driver; depending on the device configuration, this may require local access or elevated privileges. Exploitation leads to memory corruption and service disruption. Patches are expected to be available through Samsung firmware updates for affected products.

Affected products

  • Samsung Exynos 1330 unspecified
  • Samsung Exynos 1380 unspecified
  • Samsung Exynos 1480 unspecified
  • Samsung Exynos 2400 unspecified
  • Samsung Exynos 1580 unspecified
  • Samsung Exynos 2500 unspecified
  • Samsung Exynos 2600 unspecified
  • Samsung Exynos 1680 unspecified

Timeline

  • 2026-09-14: disclosed: CVE published on NVD
  • 2025-12-29: other: Reported date per Samsung advisory

References

Related threats