Impact
Samsung's libimagecodec.media.quram.so parses DNG image files and contains a flaw that triggers an out-of-bounds write when handling malformed input. A crafted malicious DNG file can be processed by the library, overwriting adjacent memory and corrupting data or control flow. The vulnerability may cause application crashes or, if key control structures are affected, could lead to more severe consequences such as privilege escalation for the app.
Affected Systems
Any Samsung mobile device that uses libimagecodec.media.quram.so before the July 2026 SMR Release 1 is impacted. No specific device models or OS revisions are listed, so users of all devices that include the unpatched library version are at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. The flaw is remote: a malicious DNG file can be delivered via email, messaging, or other file transfer methods. If the file is opened or imported, the out-of-bounds write may corrupt memory, presenting a realistic risk of arbitrary memory corruption.
OpenCVE Enrichment