Impact
The reported flaw is a stack-based buffer overflow located in the Samsung Mobile Device library component libril_sem.so. Because the vulnerability exists in a privileged system library, an attacker with local device access and sufficient privileges can potentially execute arbitrary code. The flaw directly jeopardizes confidentiality, integrity, and availability of the affected mobile devices by allowing privileged attackers to take complete control of the system.
Affected Systems
All Samsung Mobile Devices that are running firmware prior to the SMR Aug‑2026 Release 1 update are affected. The specific versions impacted are those before the release of the August 2026 security update, which contains the fix for the libril_sem.so buffer overflow.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. Although the EPSS score is not available, the lack of a listing in the CISA KEV catalog suggests that no publicly documented exploits are known at this time. The likely attack vector is local privileged, meaning an attacker must already have local access with elevated rights to succeed. Given the high CVSS, even in the absence of widespread exploitation, the vulnerability represents a significant risk for affected devices.
OpenCVE Enrichment