Description
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.
Published: 2026-07-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Samsung Mobile devices’ libimagecodec.media.quram.so component, where an out‑of‑bounds write occurs while parsing TIFF files. This flaw, classified as a classic buffer overrun (CWE‑787), can corrupt device memory when a crafted TIFF image is processed, potentially enabling arbitrary code execution or leading to a crash. The 8.4 CVSS score reflects its high severity.

Affected Systems

All Samsung Mobile devices that ship with the pre‑SMR Jul‑2026 Release 1 version of libimagecodec.media.quram.so are vulnerable. Devices that have not applied the July 2026 firmware update retain the insecure library and are at risk of exploitation via malformed TIFF files.

Risk and Exploitability

The EPSS score of <1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is remote delivery of a malicious TIFF file through any interface that triggers image parsing, such as photo viewers, message attachments, or web content. If an attacker can supply the crafted file, the out‑of‑bounds write could corrupt memory, affecting confidentiality, integrity, or availability.

Generated by OpenCVE AI on July 28, 2026 at 08:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the SMR Jul‑2026 Release 1 firmware update that includes the patched libimagecodec.media.quram.so component to all Samsung Mobile devices.
  • If the update cannot be applied immediately, restrict processing of TIFF files from untrusted sources by disabling the device’s image viewer or configuring application sandbox policies to block malformed TIFF input.
  • Disable or uninstall third‑party applications that parse TIFF images until the firmware update is available and monitor device logs for signs of memory corruption or abnormal crashes.

Generated by OpenCVE AI on July 28, 2026 at 08:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung Image Codec TIFF Parser
Weaknesses CWE-787

Thu, 23 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in TIFF Parser Leading to Memory Corruption
Weaknesses CWE-119
CWE-787

Fri, 17 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in TIFF Parser Leading to Memory Corruption
Weaknesses CWE-119
CWE-787

Thu, 16 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out TIFF Parser of Samsung libimagecodec.media.quram.so
Weaknesses CWE-787

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Out TIFF Parser of Samsung libimagecodec.media.quram.so
Weaknesses CWE-787

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in TIFF Parser Causing Remote Code Execution
Weaknesses CWE-787

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in TIFF Parser Causing Remote Code Execution
Weaknesses CWE-787

Fri, 10 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T14:34:52.799Z

Reserved: 2025-12-11T01:33:35.816Z

Link: CVE-2026-21045

cve-icon Vulnrichment

Updated: 2026-07-10T14:34:46.033Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses