Impact
A heap-based buffer overflow exists in the libimagecodec.quram.so JPEG decoder within Samsung Mobile devices. The vulnerability allows a remote attacker to trigger the overflow by supplying a carefully crafted JPEG image, leading to arbitrary code execution with the privileges of the image decoding service. The weakness is a classic heap buffer overflow, as identified by CWE-122, and compromises confidentiality, integrity, and availability of the affected device.
Affected Systems
Samsung Mobile devices that run a firmware version prior to the SMR Sep‑2026 Release 1 are impacted. No specific sub‑product or version list is supplied beyond the indication that all devices before this release are affected.
Risk and Exploitability
The CVSS score of 9.2 classifies the issue as critical. Because the EPSS score is not available, the likelihood of exploitation is unknown, though the lack of KEV listing suggests no public exploit has yet been observed. The attack vector is remote and relies on an attacker being able to deliver a malicious JPEG file to the device, either via social engineering, compromised apps, or other delivery mechanisms.
OpenCVE Enrichment