Description
Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation.

This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.
Published: 2026-07-09
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read that allows the Escargot JavaScript engine to read data from memory addresses beyond the intended buffer boundaries. A crafted input can expose sensitive data stored adjacent to the buffer and may also trigger a reachable assertion that can destabilize the engine or cause a crash. Thus an attacker who can provide malicious JavaScript is able to obtain confidential information or induce a denial‑of‑service.

Affected Systems

Samsung Open Source Escargot installations that include code before commit 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c are affected. The defect resides in the core JavaScript engine component maintained in Samsung’s public repository.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity, and the EPSS score of < 1% shows a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is the execution of specially crafted JavaScript that causes the engine to read beyond a buffer; exploitation requires an attacker to supply such input, which is common in web scenarios that render untrusted scripts. Successful exploitation can lead to disclosure of confidential data or destabilization of the runtime.

Generated by OpenCVE AI on July 28, 2026 at 08:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Escargot to a revision that incorporates the fix after commit 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c, such as the version integrated by pull request 1586.
  • Rebuild the engine from the updated source if you compile it yourself so that the patch is applied.
  • If an immediate upgrade is not feasible, isolate the execution of the JavaScript engine by restricting input to trusted sources or running the engine in a hardened sandbox that limits memory visibility, thereby reducing the risk of information leakage.

Generated by OpenCVE AI on July 28, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read and Assertion Vulnerability in Samsung Escargot JavaScript Engine

Thu, 23 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read and Assertion Vulnerability in Samsung Escargot JavaScript Engine

Thu, 16 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read and Assertion Vulnerability in Samsung Escargot JavaScript Engine

Tue, 14 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read and Assertion Vulnerability in Samsung Escargot JavaScript Engine

Mon, 13 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Escargot Out-of-Bounds Read Enables Memory Overread and Assertion Crash

Sat, 11 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Escargot Out-of-Bounds Read Enables Memory Overread and Assertion Crash

Fri, 10 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Samsung Escargot Allows Overread of Buffers

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Samsung Escargot Allows Overread of Buffers

Thu, 09 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Open Source
Samsung Open Source escargot
Vendors & Products Samsung Open Source
Samsung Open Source escargot

Thu, 09 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.
Weaknesses CWE-125
CWE-617
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Samsung Open Source Escargot
cve-icon MITRE

Status: PUBLISHED

Assigner: samsung.tv_appliance

Published:

Updated: 2026-07-09T12:04:20.924Z

Reserved: 2026-06-30T01:49:44.822Z

Link: CVE-2026-58307

cve-icon Vulnrichment

Updated: 2026-07-09T12:03:32.825Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses