Impact
An out-of-bounds write flaw in Samsung’s libsavsac.so library precedes the July 2026 Release 1 security update. The vulnerability permits remote attackers to write data beyond a buffer in the library, enabling execution of arbitrary code within the device’s context. The flaw satisfies CWE‑119 and CWE‑787, and an attacker could compromise the confidentiality, integrity, and availability of the affected device.
Affected Systems
Samsung Mobile Devices, including all models running the pre‑July 2026 Release 1 version of libsavsac.so, are affected. The advisory does not specify particular firmware levels, so any device with the unpatched library is at risk until the update is applied.
Risk and Exploitability
The CVSS score (8.7) denotes high severity; however, the EPSS (< 1%) indicates a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred to involve a remote trigger of the out-of-bounds write, such as through a malicious application or network‑facing service, which an attacker could use to achieve arbitrary code execution.
OpenCVE Enrichment