Junglewise Threat Intelligence

CVE-2026-33964: Samsung Exynos untrusted pointer dereference in camera driver

CVE-2026-33964 · Severity: medium · CVSS 6.4 · Published 2026-09-14

Technologies: Samsung Exynos 2500, Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung's Exynos mobile processors (1580 and 2500) contain a vulnerability in their camera driver that can be triggered by sending a malformed message. An attacker exploiting this flaw could cause the camera subsystem to crash, resulting in service disruption, or potentially leak sensitive information from device memory.

Technical details

The vulnerability is an untrusted pointer dereference in the camera driver of Samsung Exynos 1580 and 2500 processors. When a malformed message is sent to the camera driver, it dereferences an unsanitized pointer without proper validation, leading to information disclosure or denial of service. The attack vector requires local or adjacent network access to the camera subsystem. An attacker can cause limited information leakage from kernel memory or crash the camera service. Patch availability is indicated via Samsung's security advisory but specific version details are not provided in the referenced content.

Affected products

  • Samsung Exynos 1580 unspecified
  • Samsung Exynos 2500 unspecified

Timeline

  • 2026-09-14: disclosed: CVE published on NVD
  • 2025-12-29: other: Reported date per Samsung advisory

References

Related threats