ZeroHour

CVE-2026-21087

mass

Out-of-Bounds Write in Samsung libmdnie.so Allows System-Privilege Code Execution

CVSS 4.0
8.6 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-21087 is an out-of-bounds write in libmdnie.so, Samsung's mobile display image tuning library, affecting Samsung Android devices on builds prior to the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1). The flaw is triggered by a local attacker with no privileges and no user interaction required, consistent with a malicious local app or process reaching the display tuning component. Successful exploitation allows the attacker to execute arbitrary code with system server privileges, giving near-full control over the device's system server context. All Samsung mobile devices running affected builds are exposed, though the attack requires an foothold on the device rather than remote network access. As of now there is no known in-the-wild exploitation, no public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Update affected Samsung devices to the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1) via Settings > Software update as it becomes available for the device model and region. Until patched, limit risk by avoiding installation of untrusted or sideloaded apps, since exploitation requires a local foothold on the device. Enterprise administrators should verify fleet patch levels against the Sep-2026 SMR and prioritize devices used by high-risk or privileged users.

Affected
Samsung libmdnie.so (Samsung Android/Galaxy mobile devices)all builds prior to SMR Sep-2026 Release 1
Estimated exposure
masshundreds of millions of Samsung Galaxy devices (global Samsung Android install base; the Sep-2026 SMR is only just rolling out) — Samsung holds roughly a fifth of the global smartphone market with an active Galaxy install base estimated near a billion devices, and devices only become fully patched as the September 2026 SMR is distributed, so the vulnerable population…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.

Vendors
samsung
Products
android
Weakness
CWE-787
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.