Impact
An out-of-bounds write in the Samsung libsthmbc.so library allows local attackers to corrupt memory. The vulnerability arises when the library writes beyond its buffer boundaries, potentially overwriting critical data structures and enabling further exploitation. This type of flaw is commonly referred to as a buffer overflow weakness.
Affected Systems
Samsung Mobile devices that incorporate the libsthmbc component and run a version of One UI before 8.5. The specific affected firmware or build versions are not enumerated in the advisory, but the risk applies to any device using the vulnerable library on these older OS releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is unavailable, but the lack of KEV listing suggests no widespread exploitation in the public domain. The attack requires local access to the device, meaning physical possession or a local malicious application would be needed to trigger the overflow.
OpenCVE Enrichment