Impact
The vulnerability resides in the libcodec2secqcelpdec.so component of Samsung Mobile Devices. A local attacker can trigger an out‑of‑bounds write that corrupts adjacent memory, potentially causing application crashes, data integrity issues, or creating a foothold for further privilege escalation. The description speaks of an out‑of‑bounds write; it is inferred that this stems from improper bounds checking during codec decoding, as the flaw allows memory outside the bounds of a buffer to be written.
Affected Systems
Samsung Mobile Devices are affected, but no specific firmware or software version information is listed. The Samsung security update portal for August 2026 is the primary source for affected builds.
Risk and Exploitability
The CVSS base score of 4.4 indicates moderate severity. The EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog, implying limited public exploitation data. Based on the description, the likely attack vector is local, requiring physical access or a user process on the device to trigger the out‑of‑bounds write, which makes the risk moderate for unpatched systems.
OpenCVE Enrichment