Executive brief
Samsung Escargot is an open-source JavaScript engine used in various Samsung products like smart TVs and appliances. A vulnerability in how the engine handles memory buffers could allow a malicious script to read or write data outside of its intended boundaries. This could lead to application crashes or potentially allow an attacker to manipulate sensitive data within the device's memory.
Technical details
An out-of-bounds (OOB) read and write vulnerability exists in the Samsung Escargot JavaScript engine within the ArrayBuffer.prototype.transfer implementation. The root cause is a failure to validate that the 'newByteLength' parameter is less than or equal to the 'maxByteLength' of the buffer, leading to an assertion failure in debug builds and OOB memory access in release builds. An attacker can exploit this by providing a crafted length to the transfer method, potentially achieving arbitrary memory corruption or information disclosure within the context of the JavaScript runtime. The issue was addressed by adding proper bounds checking and throwing a RangeError when the requested length exceeds the original buffer's capacity.
Affected products
- Samsung Escargot before 779f6bedf58f334dec64b0a51ebb724b4708b84a
Timeline
- 2026-05-12: disclosed: Issue reported on GitHub
- 2026-05-27: patched: Fix merged into master branch
- 2026-07-09: advisory: CVE published to NVD