Description
Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code.
Published: 2026-09-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Patch Immediately
AI Analysis

Impact

An out‑of‑bounds write flaw in Samsung’s libsavscmn.so library permits a local attacker to overwrite legitimate memory and execute arbitrary code. By supplying crafted input that extends beyond the intended buffer, an attacker grants full device compromise, potentially allowing persistent malware to run with system privileges.

Affected Systems

The vulnerability affects Samsung Mobile devices running firmware versions prior to One UI 8.5, specifically the libsavscmn.so component that resides in the system services layer. Devices with vulnerable builds before the 8.5 release are exposed; firmware 8.5 and later are believed to contain the fix.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score is less than 1%, suggesting a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring physical access or a compromised local user session; no publicly known exploit exists yet, but the local code execution capability poses a significant threat to device integrity.

Generated by OpenCVE AI on September 10, 2026 at 23:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Samsung’s most recent One UI firmware update that includes the security fix for libsavscmn.so
  • If an update cannot be applied immediately, disable developer mode and block the installation of non‑official or rooted applications to reduce local attack exposure
  • Continuously monitor system logs for abnormal memory writes or unexpected process activity and apply subsequent security patches as they become available

Generated by OpenCVE AI on September 10, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile libsavscmn.so
Vendors & Products Samsung Mobile
Samsung Mobile libsavscmn.so

Thu, 10 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Write in Samsung libsavscmn.so Enables Local Code Execution

Thu, 10 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung’s libsavscmn.so Enables Local Arbitrary Code Execution
Weaknesses CWE-119

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Samsung’s libsavscmn.so Enables Local Arbitrary Code Execution
Weaknesses CWE-119

Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Libsavscmn.so
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-09-10T14:12:08.275Z

Reserved: 2025-12-11T01:33:35.830Z

Link: CVE-2026-21110

cve-icon Vulnrichment

Updated: 2026-09-10T14:12:02.309Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T05:17:23.497

Modified: 2026-09-10T15:17:28.973

Link: CVE-2026-21110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:19Z

Weaknesses