Executive brief
Samsung's Exynos mobile processors contain a camera driver vulnerability that leaks sensitive information through debugging code left in the driver. While the risk is low, this could expose internal data or system details to attackers with access to the camera subsystem, potentially compromising device security or user privacy.
Technical details
The vulnerability is an information disclosure flaw (CWE-215: Insertion of Sensitive Information Into Debugging Code) in the camera driver component of Samsung Exynos mobile processors. Sensitive information is embedded in debug output that may be accessible to local processes with appropriate privileges. The attack requires local access to the affected processor's camera subsystem. An attacker with local code execution or device access could extract sensitive data through the camera driver's debug interface. Samsung has acknowledged this issue and patches are available through their product security updates.
Affected products
- Samsung Exynos 1330
- Samsung Exynos 1380
- Samsung Exynos 1480
- Samsung Exynos 1580
- Samsung Exynos 1680
- Samsung Exynos 2400
- Samsung Exynos 2500
- Samsung Exynos 2600
Timeline
- 2026-09-14: disclosed
- 2025-12-15: advisory: Reported date per Samsung security page