Executive brief
Samsung's Exynos mobile processors contain a timing vulnerability in the camera driver that could allow a local attacker to access memory outside intended boundaries. This could potentially lead to information disclosure or system instability on affected mobile devices and edge computing platforms using these processors.
Technical details
A Time-of-Check Time-of-Use (TOCTOU) race condition exists in the Samsung Exynos camera driver affecting multiple processor models (1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680). The vulnerability allows out-of-bounds memory access, which can be exploited by a local attacker to read or write memory beyond intended limits. The attack requires local access to the affected device and successful timing of the race condition window. Exploitation could result in information disclosure, denial of service, or potentially privilege escalation depending on memory contents.
Affected products
- Samsung Exynos 1330 <UNKNOWN>
- Samsung Exynos 1380 <UNKNOWN>
- Samsung Exynos 1480 <UNKNOWN>
- Samsung Exynos 2400 <UNKNOWN>
- Samsung Exynos 1580 <UNKNOWN>
- Samsung Exynos 2500 <UNKNOWN>
- Samsung Exynos 2600 <UNKNOWN>
- Samsung Exynos 1680 <UNKNOWN>
Timeline
- 2026-09-14: disclosed
- 2025-12-15: other: Reported date