ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability

AI summary · glm-5.3

ZDI discloses CVE-2026-21045, a heap buffer overflow in Samsung Galaxy S25 TIFF processing enabling RCE via malicious files or pages.

ZDI-26-529 describes a heap-based buffer overflow in Samsung Galaxy S25 TIFF file processing that allows remote attackers to execute arbitrary code. User interaction is required, as the target must visit a malicious page or open a malicious file. ZDI assigned a CVSS score of 8.8, tracked as CVE-2026-21045.

  • Heap buffer overflow in Samsung Galaxy S25 TIFF file processing
  • Remote code execution possible with user interaction
  • CVSS 8.8, tracked as CVE-2026-21045

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21045
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory

Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.

NVD description · AI analysis pending
8.3<1%
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S25 devices. User interaction may be required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-21045.

This source does not provide full text. Read it at zerodayinitiative.com.