Junglewise Threat Intelligence

CVE-2026-8916: Samsung rlottie out-of-bounds write in SW_FT_Outline

CVE-2026-8916 · Severity: medium · CVSS 6.1 · Published 2026-06-04

Technologies: Samsung Rlottie. Vendors: Samsung.

Executive brief

Samsung rlottie is an open-source library used to render vector animations, commonly found in mobile apps and smart devices. A vulnerability in how it handles animation files could allow a specially crafted file to crash an application or cause it to behave unexpectedly. This could lead to service disruptions or stability issues on devices that process these animations.

Technical details

An out-of-bounds write vulnerability exists in Samsung's rlottie library due to an integer overflow in the SW_FT_Outline point and contour counters. The flaw is triggered when the library processes a maliciously crafted animation file, leading to a buffer overflow. An attacker can exploit this by convincing a user to open a specially crafted file (User Interaction required), potentially resulting in a denial-of-service (application crash) or limited data integrity impact. The issue was addressed in commit dcfde72eae1b0464dc0dd760aec00ada6a148635.

Affected products

  • Samsung rlottie before dcfde72eae1b0464dc0dd760aec00ada6a148635

Timeline

  • 2026-05-12: patched: Fix merged into master branch via pull request 589
  • 2026-06-04: disclosed: CVE published by Samsung TV & Appliance CNA

References

Related threats