Description
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.
Published: 2026-09-14
Score: 2.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch or Mitigate
AI Analysis

Impact

The flaw arises from the inclusion of sensitive data in the camera driver’s debugging code within Samsung Exynos processors. When debug output is accessed, confidential information that should remain protected can be exposed, resulting in an information leak. The weakness is an improper handling of confidential data in code that is visible to a debugging interface, identified as CWE-215.

Affected Systems

Samsung Exynos 1330 firmware and its variants—including the 1380, 1480, 2400, 1580, 2500, 2600, and 1680—are affected. The issue resides specifically in the camera driver component of these mobile processors.

Risk and Exploitability

With a CVSS score of 2.8, the vulnerability is classified as low severity. The EPSS score is below 1%, indicating a very low likelihood of exploitation. It is not listed in the CISA KEV catalog, and no public exploit is known. The attack vector is inferred to be local; an adversary would need physical or software access that allows them to read the device’s debugging output, which is normally restricted to developers or system software.

Generated by OpenCVE AI on September 15, 2026 at 16:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any Samsung firmware updates that eliminate the debugging code containing sensitive information.
  • If an update is unavailable, logging so that no confidential data is emitted.
  • Restrict privileged access to the device, limiting who can enable or read debugging interfaces, to reduce the risk of local exploitation.

Generated by OpenCVE AI on September 15, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Leak via Debugging Code in Samsung Exynos Camera Driver

Mon, 14 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Information Leak via Sensitive Data in Exynos Camera Driver Debugging Code

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Information Leak via Sensitive Data in Exynos Camera Driver Debugging Code

Mon, 14 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.
First Time appeared Samsung
Samsung exynos 1330 Firmware
Weaknesses CWE-215
CPEs cpe:2.3:a:samsung:exynos_1330_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 1330 Firmware
References
Metrics cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Samsung Exynos 1330 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:13:52.566Z

Reserved: 2026-03-24T00:00:00.000Z

Link: CVE-2026-33966

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:40.488Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T03:16:36.313

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-33966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:15:15Z

Weaknesses
  • CWE-215

    Insertion of Sensitive Information Into Debugging Code