ZeroHour

CVE-2026-21096

mass

Heap Buffer Overflow in Samsung Quram JPEG Decoder Enables Remote Code Execution

CVSS 4.0
9.2 critical
EPSS
<1%p34
Published
()
Modified
AI analysis

CVE-2026-21096 is a heap-based buffer overflow in the JPEG decoder of libimagecodec.quram.so, the Quram image codec library used in Samsung's stock image handling on mobile devices. The flaw is triggered when the device processes a maliciously crafted JPEG image; the CVSS 4.0 vector indicates a network-adjacent/remote attack with no privileges or user interaction required, though certain attack preconditions (AT:P) must be satisfied. A successful exploit allows a remote attacker to execute arbitrary code on the device, with high impact to confidentiality, integrity, and availability. All Samsung mobile devices that have not received the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1) are affected. There is currently no CISA KEV listing, no public proof-of-concept, and no known exploitation in the wild.

What to do: Update affected Samsung devices to the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1) via Settings > Software update, and verify the device's security patch level is September 2026 or later. Until patched, treat JPEG images from untrusted sources (e.g., email, messaging, and web downloads) as untrusted input, since decoding is the attack surface. Defenders should monitor Samsung's security advisory for any updated exploitation status.

Affected
Samsung Mobile devices (JPEG decoder in libimagecodec.quram.so, the Quram image codec library)All builds prior to SMR Sep-2026 Release 1 (devices whose security patch level is earlier than the September 2026 Samsung Security Maintenance Release)
Estimated exposure
mass≈1 billion+ Samsung mobile devices (Samsung's global Android smartphone/tablet install base) — The Quram image codec library ships in the stock Samsung image-decoding pipeline across Galaxy smartphones and tablets, and Samsung is the world's largest Android vendor with an active device base measured in the hundreds of millions to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Vendors
samsung
Products
android
Weakness
CWE-122
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.