ZeroHour

CVE-2026-21095

mass

Heap Buffer Overflow in Samsung libimagecodec.quram.so DNG Decoder Enables RCE

CVSS 4.0
9.2 critical
EPSS
<1%p34
Published
()
Modified
AI analysis

CVE-2026-21095 is a heap-based buffer overflow in the DNG (Digital Negative RAW) decoder of libimagecodec.quram.so, Samsung's image codec library shipped on Galaxy Android devices. The flaw is triggered when the library processes a specially crafted DNG image, and the CVSS 4.0 vector (AV:N, PR:N, UI:N) indicates it can be exploited over a network without privileges or user interaction. A successful attack allows a remote attacker to execute arbitrary code in the context of the media-processing component. All Samsung devices running a security patch level earlier than the September 2026 Samsung Maintenance Release (SMR) are affected. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.

What to do: Apply Samsung's September 2026 Maintenance Release (SMR Sep-2026 Release 1) via Settings > Software update as soon as it is available for your device. Until patched, treat DNG/RAW images from untrusted sources (messaging apps, email attachments, cloud links) with caution, as no public PoC or in-the-wild exploitation is known. Verify your device's Android security patch level shows the September 2026 (or later) Samsung security update after installing.

Affected
Samsung libimagecodec.quram.so (Samsung image codec library on Galaxy Android smartphones/tablets)All builds prior to SMR Sep-2026 Release 1 (devices on security patch levels earlier than the September 2026 Maintenance Release)
Estimated exposure
masshundreds of millions of Samsung Galaxy devices on patch levels before the September 2026 SMR — The Quram image codec library ships in Samsung's stock Android builds, and Samsung's active Galaxy installed base is estimated in the hundreds of millions to over a billion devices, nearly all of which had not received the future Sep-2026…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Vendors
samsung
Products
android
Weakness
CWE-122
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.