Description
Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.
Published: 2026-07-28
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write in Samsung Mobile’s ImsService prior to the SMR Jul‑2026 Release 1 can allow an attacker to overwrite memory, potentially executing arbitrary code. This buffer overflow, identified by CWE‑787, compromises the confidentiality, integrity, and availability of the affected device.

Affected Systems

The vulnerability affects Samsung Mobile devices published under the Samsung Mobile:Samsung Mobile Devices product line. Specific firmware or OS versions are not listed in the available data.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity rating. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the issue is not currently cataloged in CISA’s KEV list. Based on the description, the likely attack vector is remote, requiring the attacker to deliver malicious traffic that triggers the out‑of‑bounds write in ImsService.

Generated by OpenCVE AI on August 4, 2026 at 12:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Samsung security update released for Jul 2026, which patches ImsService
  • If the update cannot be applied immediately, disable or uninstall the ImsService component to stop the vulnerable code from running
  • Configure network or device policies to restrict incoming traffic that could trigger the out‑of‑bounds write, such as blocking unused ports or protocols that interact with ImsService

Generated by OpenCVE AI on August 4, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung ImsService Enables Remote Code Execution

Sat, 01 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung ImsService Enables Remote Code Execution

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-29T19:14:55.153Z

Reserved: 2025-12-11T01:33:35.817Z

Link: CVE-2026-21047

cve-icon Vulnrichment

Updated: 2026-07-28T12:16:42.696Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T12:16:36.207

Modified: 2026-07-30T16:45:56.833

Link: CVE-2026-21047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:00:11Z

Weaknesses