CVE-2026-21096
massHeap Buffer Overflow in Samsung Quram JPEG Decoder Enables Remote Code Execution
CVE-2026-21096 is a heap-based buffer overflow in the JPEG decoder of libimagecodec.quram.so, the Quram image codec library used in Samsung's stock image handling on mobile devices. The flaw is triggered when the device processes a maliciously crafted JPEG image; the CVSS 4.0 vector indicates a network-adjacent/remote attack with no privileges or user interaction required, though certain attack preconditions (AT:P) must be satisfied. A successful exploit allows a remote attacker to execute arbitrary code on the device, with high impact to confidentiality, integrity, and availability. All Samsung mobile devices that have not received the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1) are affected. There is currently no CISA KEV listing, no public proof-of-concept, and no known exploitation in the wild.
What to do: Update affected Samsung devices to the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1) via Settings > Software update, and verify the device's security patch level is September 2026 or later. Until patched, treat JPEG images from untrusted sources (e.g., email, messaging, and web downloads) as untrusted input, since decoding is the attack surface. Defenders should monitor Samsung's security advisory for any updated exploitation status.
| Samsung Mobile devices (JPEG decoder in libimagecodec.quram.so, the Quram image codec library) | All builds prior to SMR Sep-2026 Release 1 (devices whose security patch level is earlier than the September 2026 Samsung Security Maintenance Release) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-122
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.