Impact
A flaw in Samsung’s codec library, libcodec2secqcelpdec.so, permits local attackers to write outside the bounds of a buffer. The vulnerability results in memory corruption in the affected process, but the CVE documentation does not detail additional consequences such as crashes or privilege escalation.
Affected Systems
Samsung Mobile Devices running firmware released prior to SMR Aug-2026 Release 1 contain the vulnerable library. Devices that have applied the August 2026 firmware update are considered patched.
Risk and Exploitability
The base CVSS score of 4.4 indicates moderate severity. The EPSS score of less than 1 % and the absence from the CISA KEV catalog suggest a low likelihood of public exploitation. The likely attack vector is local access to a process that loads the vulnerable library, which is inferred from the description of a local out-of-bounds write.
OpenCVE Enrichment