Impact
The vulnerability is a stack‑based buffer overflow in the PROCA trustlet available on Samsung Mobile Devices before the SMR Sep‑2026 Release overflow to write data beyond the intended memory bounds, potentially corrupting critical memory and enabling further compromise. The weakness is a classic buffer overflow, a type of memory corruption flaw.
Affected Systems
Samsung Mobile Devices running the PROCA trustlet version that predates SMR Sep‑2026 Release 1. No specific version numbers are provided, but all firmware revisions before that release are affected.
Risk and Exploitability
The CVSS score of 5.6 indicates a medium severity issue. The EPSS score of < 1% indicates a very low probability of exploitation, although the exploit requires local privileged access, limiting the attacker scope. The vulnerability is not yet listed in CISA KEV, suggesting that widespread exploitation has not yet occurred, meaning that an attacker with administrative or root access on the device could exploit it to corrupt memory or facilitate further attacks.
OpenCVE Enrichment