Junglewise Threat Intelligence

CVE-2026-58304: Samsung Escargot out-of-bounds read and write in ArrayBuffer

CVE-2026-58304 · Severity: medium · CVSS 6.1 · Published 2026-07-09

Technologies: Samsung Escargot. Vendors: Samsung.

Executive brief

Samsung Escargot is an open-source JavaScript engine used in various Samsung products like smart TVs and appliances. A vulnerability in how the engine handles memory buffers could allow a malicious script to read or write data outside of its intended boundaries. This could lead to application crashes or potentially allow an attacker to manipulate sensitive data within the device's memory.

Technical details

An out-of-bounds (OOB) read and write vulnerability exists in the Samsung Escargot JavaScript engine within the ArrayBuffer.prototype.transfer implementation. The root cause is a failure to validate that the 'newByteLength' parameter is less than or equal to the 'maxByteLength' of the buffer, leading to an assertion failure in debug builds and OOB memory access in release builds. An attacker can exploit this by providing a crafted length to the transfer method, potentially achieving arbitrary memory corruption or information disclosure within the context of the JavaScript runtime. The issue was addressed by adding proper bounds checking and throwing a RangeError when the requested length exceeds the original buffer's capacity.

Affected products

  • Samsung Escargot before 779f6bedf58f334dec64b0a51ebb724b4708b84a

Timeline

  • 2026-05-12: disclosed: Issue reported on GitHub
  • 2026-05-27: patched: Fix merged into master branch
  • 2026-07-09: advisory: CVE published to NVD

References

Related threats