Impact
The vulnerability is a Time-of-Check Time-of-Use race condition in the camera driver of Samsung Exynos processors. This flaw can cause an out-of-bounds memory access, potentially corrupting memory and leading to application crashes, device instability, or denial of service. The weakness is classified as a boundary error (CWE-125).
Affected Systems
Firmware for Samsung Exynos 1330 and several other variants—including 1380, 1480, 2400, 1580, 2500, 2600, and 1680—is affected and the vulnerability is already present in these firmware releases, pending a Samsung patch.
Risk and Exploitability
The CVSS score of 2.8 indicates low severity. The EPSS score is under 1 % and the vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to require local device access, as the issue originates in the camera driver, and the description does not specify remote exploitation corruption could cause device crashes or denial of service. Overall risk remains moderate, making monitoring and patching prudent.
OpenCVE Enrichment