Description
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.
Published: 2026-09-14
Score: 2.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds memory corruption in camera driver
Action: Monitor
AI Analysis

Impact

The vulnerability is a Time-of-Check Time-of-Use race condition in the camera driver of Samsung Exynos processors. This flaw can cause an out-of-bounds memory access, potentially corrupting memory and leading to application crashes, device instability, or denial of service. The weakness is classified as a boundary error (CWE-125).

Affected Systems

Firmware for Samsung Exynos 1330 and several other variants—including 1380, 1480, 2400, 1580, 2500, 2600, and 1680—is affected and the vulnerability is already present in these firmware releases, pending a Samsung patch.

Risk and Exploitability

The CVSS score of 2.8 indicates low severity. The EPSS score is under 1 % and the vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to require local device access, as the issue originates in the camera driver, and the description does not specify remote exploitation corruption could cause device crashes or denial of service. Overall risk remains moderate, making monitoring and patching prudent.

Generated by OpenCVE AI on September 15, 2026 at 17:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Samsung firmware update that fixes the camera driver race condition when it is released, restrict or disable camera functionality on the affected devices to prevent the race condition from being triggered.
  • Monitor device logs for camera-related crashes or abnormal behavior and report any incidents to Samsung support.
  • Restrict camera access at the operating‑system level by disabling the camera driver in the device’s BIOS/firmware registry or applying application permission controls to block non‑essential applications from using the camera.

Generated by OpenCVE AI on September 15, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Time-of-Check Time-of-Use Race Condition in Samsung Exynos Camera Driver

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Exynos Camera Driver TOCTOU Race Condition Causing Out-of-Bounds Access

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Exynos Camera Driver TOCTOU Race Condition Causing Out-of-Bounds Access

Mon, 14 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.
First Time appeared Samsung
Samsung exynos 1330 Firmware
Weaknesses CWE-125
CPEs cpe:2.3:a:samsung:exynos_1330_firmware:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung exynos 1330 Firmware
References
Metrics cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L'}


Subscriptions

Samsung Exynos 1330 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:12:59.064Z

Reserved: 2026-03-24T00:00:00.000Z

Link: CVE-2026-33968

cve-icon Vulnrichment

Updated: 2026-09-14T15:12:54.061Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T03:16:36.607

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-33968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses