Impact
An out‑of‑bounds write flaw exists in the libsaviextractor.so component of local attacker to corrupt memory by overwriting data beyond the intended bounds. While the description does not specify a higher‑level effect, memory corruption can result in application crashes, data loss, or potentially untrusted code execution if the overwritten area influences control flow.
Affected Systems
Samsung Mobile Devices running the SMR framework before the September 2026 Release 1 firmware update are affected. The issue is tied to the libsaviextractor.so library; no specific device models or firmware versions are enumerated beyond the Samsung Mobile Products.
Risk and Exploitability
The CVSS score of 4.4 reflects a moderate severity of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. It requires local presence on the device; there are no known remote or privilege escalation vectors. The EPSS score of <1% indicates a very low probability that this vulnerability will be exploited in the wild. Consequently, the immediate risk is confined to memory corruption on unpatched devices, potentially leading to instability or data loss.
OpenCVE Enrichment