Impact
An out‑of‑bounds write flaw in Samsung’s libsavscmn.so library permits a local attacker to overwrite legitimate memory and execute arbitrary code. By supplying crafted input that extends beyond the intended buffer, an attacker grants full device compromise, potentially allowing persistent malware to run with system privileges.
Affected Systems
The vulnerability affects Samsung Mobile devices running firmware versions prior to One UI 8.5, specifically the libsavscmn.so component that resides in the system services layer. Devices with vulnerable builds before the 8.5 release are exposed; firmware 8.5 and later are believed to contain the fix.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score is less than 1%, suggesting a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring physical access or a compromised local user session; no publicly known exploit exists yet, but the local code execution capability poses a significant threat to device integrity.
OpenCVE Enrichment