Impact
An out‑of‑bounds write flaw exists in the libcodec2secevrcdec.so library on Samsung Mobile devices. The vulnerability allows a local attacker to cause a memory write beyond the intended buffer, which can corrupt adjacent memory structures. The description does not indicate that this corruption leads to code execution; it could, however, cause application crashes or unexpected behavior on the affected device.
Affected Systems
Samsung Mobile devices that include the libcodec2secevrcdec.so library. All devices running the library prior to the September 2026 release are potentially affected; no specific firmware or software version is listed.
Risk and Exploitability
The CVSS score of 4.4 indicates a low severity local impact. The EPSS score of <1% signals an extremely low exploitation probability. The vulnerability is not listed in KEV. Because it requires local access to trigger the codec, the risk is confined to local applications or users with sufficient device privileges.
OpenCVE Enrichment