Executive brief
Samsung Escargot, an open-source JavaScript engine often used in smart TVs and appliances, contains a memory management flaw. If a user is tricked into running a malicious script or opening a specially crafted file, an attacker could potentially crash the application or execute unauthorized code. This could lead to a loss of device control or the exposure of sensitive information stored on the device.
Technical details
An out-of-bounds (OOB) write vulnerability exists in Samsung's Escargot JavaScript engine (specifically affecting commit 590345c). The flaw is categorized as CWE-787 and stems from improper bounds checking or pointer validation during memory operations, including issues identified in BuiltinTypedArray and JSON processing. An attacker can exploit this by providing malicious JavaScript content that triggers an overflow, leading to memory corruption. While the attack vector is local, it requires minimal privileges but does necessitate user interaction (UI:R), such as a user visiting a malicious site or executing a script. Successful exploitation can result in a complete compromise of confidentiality, integrity, and availability (C/I/A). A fix has been merged into the master branch via pull request #1565.
Affected products
- Samsung Escargot 590345cc6258317c5da850d846ce6baaf2afc2d3
Timeline
- 2026-04-28: other: Initial fix pull request submitted on GitHub
- 2026-05-14: patched: Fix merged into master branch
- 2026-05-19: advisory: CVE published by Samsung TV & Appliance CNA