ZeroHour

CVE-2026-23789

mass

Double-Free in Samsung Exynos MFC Encoder Driver Enables Kernel Code Execution

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

A double-free flaw (CWE-415) in the Multi-Format Codec (MFC) encoder driver of Samsung's Exynos mobile and wearable processors is caused by improper cleanup of dma_buf references during error handling, corrupting kernel memory. It is triggered locally — for example by a malicious or compromised app that reaches the video encoder and forces the driver down a failure path — and yields kernel-level arbitrary code execution with a sandbox escape (CVSS 3.1: 7.8, AV:L/AC:H/PR:L/S:C). The affected silicon spans a broad range of Samsung Galaxy smartphones (from budget Exynos 850-class devices through flagship Exynos 2200/2400 parts) and Galaxy Watch wearables built on W920, W930, and W1000. Exploitation requires low privileges but high attack complexity (reliably racing the error path), making it most valuable as an elevation/sandbox-escape stage in a chained attack rather than a remote vector. No public proof-of-concept is known and the flaw is not in the CISA KEV, so exploitation status is currently none known.

What to do: Install the latest Samsung security software update (OTA, per the Samsung Monthly Security Bulletin) on all Galaxy phones and watches built on the listed Exynos SoCs, and verify the device's security patch level. Because the flaw is local and typically reached via media encoding from an app, restrict sideloaded and untrusted applications on managed devices. There is no effective workaround short of patching the kernel driver, so enterprise fleets should enforce minimum patch baselines via MDM.

Affected
Samsung Exynos MFC encoder driver (Samsung Mobile Processor / Wearable Processor)Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, W1000
Estimated exposure
massHundreds of millions of devices shipped with affected Exynos SoCs; number still unpatched unknown — Exynos variants of Samsung's Galaxy S21/S22/S24-class flagships, high-volume Exynos-powered Galaxy A-series midrange models, and Galaxy Watch lines built on the affected W-series chips have cumulative shipments well into the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.

Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.