Impact
An out-of-bounds write flaw exists in Samsung’s libsavsac.so library that precedes the July 2026 Release 1 security update. The vulnerability allows a local attacker—someone with physical access or the ability to run privileged code—to write data past the end of a buffer in the library, thereby enabling execution of arbitrary code in the device’s context. The flaw satisfies CWE‑119 and CWE‑787, and an attacker could compromise the confidentiality, integrity, and availability of the affected device.
Affected Systems
Samsung Mobile Devices, including all models running the pre‑July 2026 Release 1 version of libsavsac.so, are affected. The advisory does not specify particular firmware levels, so any device with the unpatched library is at risk until the update is applied.
Risk and Exploitability
The CVSS score (8.4) denotes high severity; however, the EPSS (< 1%) indicates a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers must acquire local access—such as physical possession of the device or the capability to run privileged code—to trigger the out-of-bounds write and achieve arbitrary code execution.
OpenCVE Enrichment