CVE-2026-21095
massHeap Buffer Overflow in Samsung libimagecodec.quram.so DNG Decoder Enables RCE
CVE-2026-21095 is a heap-based buffer overflow in the DNG (Digital Negative RAW) decoder of libimagecodec.quram.so, Samsung's image codec library shipped on Galaxy Android devices. The flaw is triggered when the library processes a specially crafted DNG image, and the CVSS 4.0 vector (AV:N, PR:N, UI:N) indicates it can be exploited over a network without privileges or user interaction. A successful attack allows a remote attacker to execute arbitrary code in the context of the media-processing component. All Samsung devices running a security patch level earlier than the September 2026 Samsung Maintenance Release (SMR) are affected. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Apply Samsung's September 2026 Maintenance Release (SMR Sep-2026 Release 1) via Settings > Software update as soon as it is available for your device. Until patched, treat DNG/RAW images from untrusted sources (messaging apps, email attachments, cloud links) with caution, as no public PoC or in-the-wild exploitation is known. Verify your device's Android security patch level shows the September 2026 (or later) Samsung security update after installing.
| Samsung libimagecodec.quram.so (Samsung image codec library on Galaxy Android smartphones/tablets) | All builds prior to SMR Sep-2026 Release 1 (devices on security patch levels earlier than the September 2026 Maintenance Release) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-122
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.