Description
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption.
Published: 2026-09-14
Score: 2.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Patch
AI Analysis

Impact

An out-of-bounds array access in the error-handling path of the Samsung Exynos camera driver causes memory corruption. The corrupted memory may lead to unpredictable behavior or instability in the camera subsystem, potentially affecting device operation.

Affected Systems

The vulnerability affects Samsung microprocessor firmware for Exynos 1330, as well as several other models listed in the description: 1380, 1480, 2400, 1580, 2500, 2600, and 1680. Devices running these processor families with the current camera firmware are at risk.

Risk and Exploitability

The CVSS score of 2.8 indicates a low-severity flaw. An exploit would likely require local code execution on the device that can trigger an error in the camera driver, such as a malicious application invoking camera functions. The EPSS score of <1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation at present. The attack vector is inferred as local because the flaw only interacts with local applications.

Generated by OpenCVE AI on September 15, 2026 at 15:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Samsung firmware update that addresses CVE-2026-33967.
  • If an update is not yet available, disable or restrict camera functionality to prevent the possibility of memory corruption.
  • Monitor device logs for camera-related errors or crashes and investigate any anomalous activity.

Generated by OpenCVE AI on September 15, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Samsung Exynos Camera Driver Out-of-Bounds Array Access Leading to Memory Corruption

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Access in Samsung Exynos Camera Driver Causes Memory Corruption

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Access in Samsung Exynos Camera Driver Causes Memory Corruption

Mon, 14 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption.
First Time appeared Samsung
Samsung exynos 1330 Firmware
Weaknesses CWE-787
CPEs cpe:2.3:a:samsung:exynos_1330_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 1330 Firmware
References
Metrics cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L'}


Subscriptions

Samsung Exynos 1330 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:49:47.606Z

Reserved: 2026-03-24T00:00:00.000Z

Link: CVE-2026-33967

cve-icon Vulnrichment

Updated: 2026-09-14T16:49:42.571Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T03:16:36.463

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-33967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:00:17Z

Weaknesses