ZeroHour

CVE-2026-33963

mass

Stack-Based Buffer Overflow in Samsung Exynos Camera Driver (Nine Mobile SoCs)

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

A stack-based buffer overflow (CWE-121) exists in the camera driver of nine Samsung Exynos mobile processors: the 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. The flaw is triggered when a malformed message is sent to the camera driver; per the CVSS 3.1 vector (AV:L/AC:H/PR:L/UI:N), exploitation requires local access with only low privileges on an affected device and no user interaction. The CVE description characterizes the impact as denial of service, though the assigned 7.5 rating also scores high integrity and availability impact with changed scope, so memory corruption in the camera subsystem beyond a simple crash is plausible. Affected devices are primarily Samsung Galaxy smartphones and tablets built on these SoCs, spanning high-volume mid-range models and regional flagship variants. No public proof of concept is known, the issue is not listed in CISA's KEV, and there is no evidence of exploitation in the wild.

What to do: Apply Samsung's security maintenance release containing the camera driver fix as soon as it ships, and verify the patch level on affected devices via Settings > Software update > Download and install. Because exploitation requires local low-privilege access, avoid sideloading or installing untrusted apps on devices using Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, or 1680. Monitor Samsung's monthly/quarterly Android security bulletins for the specific firmware patch covering this issue if one has not yet reached your model.

Affected
Samsung Mobile Processor Exynos 1330 (camera driver)
Samsung Mobile Processor Exynos 1380 (camera driver)
Samsung Mobile Processor Exynos 1480 (camera driver)
Samsung Mobile Processor Exynos 2400 (camera driver)
Samsung Mobile Processor Exynos 1580 (camera driver)
Samsung Mobile Processor Exynos 2500 (camera driver)
Samsung Mobile Processor Exynos 2600 (camera driver)
Samsung Mobile Processor Exynos 1680 (camera driver)
Estimated exposure
mass≈100 million+ devices (order of magnitude; cumulative Samsung Galaxy units built on these SoCs) — These SoCs power Samsung's highest-volume product lines — the Exynos 1330/1380/1480/1580 appear in mass-market Galaxy A-series phones (e.g., A14/A15, A54/A35, A55, A56 class devices) and the Exynos 2400 powers Galaxy S24/S24+ variants sold…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.

Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.