Impact
Improper input validation in the DualDAR driver enables an attacker who already has local privileges to trigger arbitrary code execution with root rights. The flaw arises when the driver fails to properly filter or sanitize input data, allowing an attacker to supply crafted payloads that the driver processes with elevated privileges. This can lead to full system compromise, data modification, and unprivileged user accounts gaining root-level control.
Affected Systems
Samsung Mobile Devices using DualDAR driver versions prior to SMR Sep-2026 Release 1 are impacted. The specific affected firmware and device models are not enumerated, but any device running the vulnerable driver version is at risk.
Risk and Exploitability
With a CVSS score of 8.4 the vulnerability is classified as high severity. The EPSS score is not available, but the lack of a KEV listing suggests that no widespread exploitation has been observed yet. The attacker must already be running on the device with local privileges; once this condition is met, exploitation is straightforward and leads to root execution. Because the vector is local, physical or malware‐based access is required to gain the initial foothold.
OpenCVE Enrichment