Impact
Samsung devices employ a library that removes style tags from content. In the version prior to SMR Sep-2026 Release 1, the input validation used to process these tags is insufficient, allowing a local attacker with access to the library to write beyond the bounds of allocated memory. Such a corruption can compromise file integrity, lead to application crashes, or potentially enable arbitrary code execution depending on the memory area affected.
Affected Systems
The flaw affects Samsung mobile devices that run the SMR operating system prior to the Sep-2026 Release 1 firmware update. All devices whose software stack includes the vulnerable libsubextractor.so instance are impacted.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The exploit is local, requiring the attacker to interact with the device or run code on it to trigger the style tag removal logic. The OOB write presents a realistic risk of data corruption or arbitrary code execution if an attacker can supply crafted input to the vulnerable component.
OpenCVE Enrichment