Junglewise Threat Intelligence

CVE-2026-58305: Samsung Escargot type confusion in array spread operations

CVE-2026-58305 · Severity: medium · CVSS 6.1 · Published 2026-07-09

Technologies: Samsung Escargot. Vendors: Samsung.

Executive brief

Samsung Escargot is an open-source JavaScript engine used in various Samsung products like smart TVs and appliances. A flaw in how the engine handles data types could allow an attacker to manipulate memory pointers, potentially leading to application crashes or unauthorized system behavior. This could impact the reliability of the device or be used as part of a more complex attack chain.

Technical details

A type confusion vulnerability exists in Samsung's Escargot JavaScript engine within the 'arrayDefineOwnPropertyBySpreadElementOperation' function. The issue arises from a failure to correctly validate object layouts when switching between 'Fast' and 'Slow' array modes during spread element operations. An attacker can exploit this by providing specially crafted JavaScript code that triggers an incompatible type access, leading to pointer manipulation and a segmentation fault (SEGV). The vulnerability was identified via an assertion failure in the ByteCodeInterpreter and is fixed in commit 779f6bedf58f334dec64b0a51ebb724b4708b84a.

Affected products

  • Samsung Escargot before 779f6bedf58f334dec64b0a51ebb724b4708b84a

Timeline

  • 2026-05-13: disclosed: Issue reported on GitHub repository
  • 2026-05-27: patched: Fix merged into master branch
  • 2026-07-09: advisory: CVE published to NVD

References

Related threats