Impact
Improper input validation in libcodec2_sec_flacdec.so allows local attackers to write out‑of‑bounds memory by crafting malicious FLAC files. This flaw can corrupt process memory, potentially leading to crashes, denial of service, or unintended behavior within the media playback subsystem.
Affected Systems
Samsung Mobile Devices running firmware versions prior to SMR Aug‑2026 Release 1 are affected. No specific firmware revision numbers are listed, so all devices operating the vulnerable library version are considered at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates medium severity, and the lack of an EPSS score means current exploitation probability is unknown. The vulnerability is not listed in CISA KEV, and it requires local access with the ability to supply a malicious FLAC file. While it does not provide remote access, a successful out‑of‑bounds write could lead to memory corruption and potential privilege escalation on the device if the exploited process has elevated permissions.
OpenCVE Enrichment