Impact
An out-of-bounds write in libpadm.so allows a local attacker to overwrite adjacent memory and execute arbitrary code (CWE‑787). It compromises the integrity of the device’s execution environment and requires local access or privileges.
Affected Systems
Samsung Mobile Devices running firmware versions prior to the SMR Jul‑2026 Release 1 that include libpadm.so. No specific device models or OS were disclosed, so any device not updated to the July 2026 SMR is presumed vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity local code execution risk. The EPSS score of less than 1% suggests that exploitation is unlikely to be widely observed at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local, so a threat actor would need physical or local access to the device to exploit this memory corruption flaw.
OpenCVE Enrichment