Impact
An out‑of‑bounds write flaw (CWE-787) exists in libmdnie.so, enabling a local attacker to execute arbitrary code with system server privilege. This vulnerability would allow the attacker to take full control of critical system services and compromise device integrity. The issue is a classic buffer overflow that can corrupt memory locations not intended by the application.
Affected Systems
Samsung Mobile Devices running a to the SMR Sep‑2026 Release 1 are impacted. No specific version numbers are provided beyond the requirement that the library predates the September 2026 release.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. EPSS score of 0.00121 indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely known exploits yet. The likely attack vector is local: an attacker must already have access to the device, but once the flaw is triggered they gain full system server privileges, making this a critical risk for any compromised or misused device.
OpenCVE Enrichment