Executive brief
Samsung's Exynos mobile processors (1580 and 2500) contain a vulnerability in their camera driver that can be triggered by sending a malformed message. An attacker exploiting this flaw could cause the camera subsystem to crash, resulting in service disruption, or potentially leak sensitive information from device memory.
Technical details
The vulnerability is an untrusted pointer dereference in the camera driver of Samsung Exynos 1580 and 2500 processors. When a malformed message is sent to the camera driver, it dereferences an unsanitized pointer without proper validation, leading to information disclosure or denial of service. The attack vector requires local or adjacent network access to the camera subsystem. An attacker can cause limited information leakage from kernel memory or crash the camera service. Patch availability is indicated via Samsung's security advisory but specific version details are not provided in the referenced content.
Affected products
- Samsung Exynos 1580 unspecified
- Samsung Exynos 2500 unspecified
Timeline
- 2026-09-14: disclosed: CVE published on NVD
- 2025-12-29: other: Reported date per Samsung advisory