Impact
An out-of-bounds array access in the error-handling path of the Samsung Exynos camera driver causes memory corruption. The corrupted memory may lead to unpredictable behavior or instability in the camera subsystem, potentially affecting device operation.
Affected Systems
The vulnerability affects Samsung microprocessor firmware for Exynos 1330, as well as several other models listed in the description: 1380, 1480, 2400, 1580, 2500, 2600, and 1680. Devices running these processor families with the current camera firmware are at risk.
Risk and Exploitability
The CVSS score of 2.8 indicates a low-severity flaw. An exploit would likely require local code execution on the device that can trigger an error in the camera driver, such as a malicious application invoking camera functions. The EPSS score of <1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation at present. The attack vector is inferred as local because the flaw only interacts with local applications.
OpenCVE Enrichment