CVE-2026-21087
massOut-of-Bounds Write in Samsung libmdnie.so Allows System-Privilege Code Execution
CVE-2026-21087 is an out-of-bounds write in libmdnie.so, Samsung's mobile display image tuning library, affecting Samsung Android devices on builds prior to the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1). The flaw is triggered by a local attacker with no privileges and no user interaction required, consistent with a malicious local app or process reaching the display tuning component. Successful exploitation allows the attacker to execute arbitrary code with system server privileges, giving near-full control over the device's system server context. All Samsung mobile devices running affected builds are exposed, though the attack requires an foothold on the device rather than remote network access. As of now there is no known in-the-wild exploitation, no public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Update affected Samsung devices to the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1) via Settings > Software update as it becomes available for the device model and region. Until patched, limit risk by avoiding installation of untrusted or sideloaded apps, since exploitation requires a local foothold on the device. Enterprise administrators should verify fleet patch levels against the Sep-2026 SMR and prioritize devices used by high-risk or privileged users.
| Samsung libmdnie.so (Samsung Android/Galaxy mobile devices) | all builds prior to SMR Sep-2026 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-787
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.