Impact
The vulnerability is a heap-based buffer overflow in the DNG decoder of libimagecodec.quram.so in Samsung Mobile Devices. It permits remote attackers to execute arbitrary code on the device, which can compromise confidentiality, integrity, and availability. The weakness is a classic buffer overrun (CWE-122).
Affected Systems
Samsung Mobile Devices running firmware prior to the SMR September 2026 Release 1. Devices that have not yet been updated to this release are susceptible; the exact affected component is the libimagecodec.quram.so library within the DNG decoder.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity. EPSS information is not provided, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, inferred from the description that remote attackers can exploit the flaw; an attacker would need to supply a vulnerable DNG file to trigger the overflow.
OpenCVE Enrichment