Impact
Improper input validation in the libsmsd.so shared library exposes a write‑to‑out‑of‑bounds condition that can be abused by local users to corrupt memory. The CVE description only indicates memory corruption; no direct statement is made about crashes, privilege escalation, or arbitrary code execution. Based on the nature of out‑of‑bounds writes, it is inferred that an attacker could potentially cause these effects, but such consequences are not confirmed in the CVE data.
Affected Systems
Samsung Mobile Devices running libsmsd.so prior to the SMR Aug‑2026 Release 1 are vulnerable. No specific version numbers are supplied, so any device incorporating the older library build is potentially affected and should be verified against the latest security update.
Risk and Exploitability
The CVSS base score of 5.1 indicates moderate severity, and the EPSS score of < 1% indicates a low probability of exploitation. Because the flaw requires local access to the device, the likelihood of widespread exploitation is limited, but the vulnerability remains significant for targeted attacks. As it is not listed in the CISA KEV catalog, there is no known active exploitation in the wild at this time.
OpenCVE Enrichment