Junglewise Threat Intelligence

CVE-2026-33967: Samsung Exynos camera driver out-of-bounds array access

CVE-2026-33967 · Severity: low · CVSS 2.8 · Published 2026-09-14

Technologies: Samsung Exynos 1480, Samsung Exynos 1380, Samsung Exynos 2400, Samsung Exynos 1680, Samsung Exynos 1330, Samsung Exynos 2500, Samsung Exynos 2600, Samsung Exynos 1580. Vendors: Samsung.

Executive brief

Samsung's Exynos mobile processors include a camera driver used in smartphones and mobile devices. A vulnerability in the camera driver's error-handling code allows out-of-bounds memory access, which can corrupt device memory and potentially lead to device malfunction or enable further attacks.

Technical details

The vulnerability is an out-of-bounds array access flaw in the camera driver component of Samsung Exynos mobile processors. The flaw exists in the error-handling path, where insufficient bounds checking allows an attacker to access memory beyond the intended array boundaries, resulting in memory corruption. The attack requires local access to the device and likely involves triggering specific camera error conditions. An attacker can cause memory corruption that may lead to denial of service or, in certain scenarios, code execution. Patches are available from Samsung through firmware updates for affected Exynos processors.

Affected products

  • Samsung Exynos 1330
  • Samsung Exynos 1380
  • Samsung Exynos 1480
  • Samsung Exynos 1580
  • Samsung Exynos 1680
  • Samsung Exynos 2400
  • Samsung Exynos 2500
  • Samsung Exynos 2600

Timeline

  • 2026-09-14: disclosed
  • 2025-12-15: advisory: Reported date per Samsung advisory

References

Related threats