Impact
The vulnerability resides in Samsung Mobile devices’ libimagecodec.media.quram.so component, where an out‑of‑bounds write occurs while parsing TIFF files. This flaw, classified as a classic buffer overrun (CWE‑787), can corrupt device memory when a crafted TIFF image is processed, potentially enabling arbitrary code execution or leading to a crash. The 8.4 CVSS score reflects its high severity.
Affected Systems
All Samsung Mobile devices that ship with the pre‑SMR Jul‑2026 Release 1 version of libimagecodec.media.quram.so are vulnerable. Devices that have not applied the July 2026 firmware update retain the insecure library and are at risk of exploitation via malformed TIFF files.
Risk and Exploitability
The EPSS score of <1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is remote delivery of a malicious TIFF file through any interface that triggers image parsing, such as photo viewers, message attachments, or web content. If an attacker can supply the crafted file, the out‑of‑bounds write could corrupt memory, affecting confidentiality, integrity, or availability.
OpenCVE Enrichment