Description
Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.

This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.
Published: 2026-07-09
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Samsung’s open‑source JavaScript engine, Escargot, contains a type‑confusion flaw (CWE‑843) that permits an attacker to manipulate pointers. The vulnerability stems from accepting incompatible types, which can corrupt memory when the engine executes JavaScript that triggers the wrong type handling. This pointer manipulation exposes the process to potential memory corruption, though the official description does not confirm arbitrary code execution or full process control.

Affected Systems

All releases of Samsung Open Source Escargot prior to commit 779f6bedf58f334dec64b0a51ebb724b4708b84a are affected. Users operating any earlier version of the engine may be exposed to this flaw.

Risk and Exploitability

The CVSS score of 6.1 represents moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of this assessment. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploitation. Attacks likely require untrusted or malicious JavaScript passing through Escargot; given the type‑confusion nature, accidental exploitation could lead to memory corruption, but the description does not confirm arbitrary code execution or full process control.

Generated by OpenCVE AI on July 26, 2026 at 15:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Escargot to the patched commit 779f6bedf58f334dec64b0a51ebb724b4708b84a
  • If an immediate upgrade is not possible, isolate or restrict execution of untrusted JavaScript that flows through Escargot to mitigate pointer manipulation
  • Monitor runtime logs and memory usage for indications of corruption and enable core dumps to assist forensic analysis

Generated by OpenCVE AI on July 26, 2026 at 15:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Escargot Type Confusion Allowing Pointer Manipulation

Wed, 22 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Type Confusion Vulnerability in Escargot Allows Pointer Manipulation

Thu, 16 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Type Confusion Vulnerability in Escargot Allows Pointer Manipulation

Mon, 13 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Type confusion in Escargot allows pointer manipulation leading to memory corruption

Sun, 12 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Type confusion in Escargot allows pointer manipulation leading to memory corruption

Sat, 11 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Escargot Type Confusion Causing Pointer Manipulation

Fri, 10 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Escargot Type Confusion Causing Pointer Manipulation

Thu, 09 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Open Source
Samsung Open Source escargot
Vendors & Products Samsung Open Source
Samsung Open Source escargot

Thu, 09 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Samsung Open Source Escargot
cve-icon MITRE

Status: PUBLISHED

Assigner: samsung.tv_appliance

Published:

Updated: 2026-07-09T12:13:38.936Z

Reserved: 2026-06-30T01:49:44.822Z

Link: CVE-2026-58305

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T15:45:08Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')