Impact
An out‑of‑bounds write in Samsung Mobile’s ImsService prior to the SMR Jul‑2026 Release 1 can allow an attacker to overwrite memory, potentially executing arbitrary code. This buffer overflow, identified by CWE‑787, compromises the confidentiality, integrity, and availability of the affected device.
Affected Systems
The vulnerability affects Samsung Mobile devices published under the Samsung Mobile:Samsung Mobile Devices product line. Specific firmware or OS versions are not listed in the available data.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity rating. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the issue is not currently cataloged in CISA’s KEV list. Based on the description, the likely attack vector is remote, requiring the attacker to deliver malicious traffic that triggers the out‑of‑bounds write in ImsService.
OpenCVE Enrichment