ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 13 sources: “ZDI publishes ten advisories on 2026-09-16/17: six unpatched 0days (Airbyte, BusyBox, CrewAI, MindsDB, Windows HTTP Proxy) plus Cisco FMC, NoMachine, GIMP and Samsung rlottie flaws” — merged summary and timeline →

ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability

highAdvisoryimportance 44CVE-2026-91826
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-91826, a stack-based buffer overflow in Samsung's rlottie animation library enabling remote code execution, rated CVSS 7.8.

ZDI-26-714 describes a stack-based buffer overflow in Samsung's rlottie library that allows remote attackers to execute arbitrary code on affected installations. Exploitation requires interaction with the rlottie library, and attack vectors vary depending on the implementation. ZDI assigned a CVSS score of 7.8 and the issue is tracked as CVE-2026-91826; no exploitation or PoC is mentioned.

  • Stack-based buffer overflow allows remote code execution on affected installations
  • Exploitation requires interaction with rlottie; attack vectors vary by implementation
  • CVSS 7.8 rating assigned by the Zero Day Initiative
  • No mention of in-the-wild exploitation or public PoC

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-91826
Stack-Based Buffer Overflow in Samsung rLottie Animation Renderer

CVE-2026-91826 is a stack-based buffer overflow (CWE-121) in Samsung's open-source rLottie library, which renders Lottie vector animations. It is triggered when the library processes a specially crafted vector animation file, overflowing a stack buffer and corrupting memory; Samsung's CVSS scoring (AV:L/UI:R) indicates a local vector requiring user interaction, while ZDI's advisory headline characterizes the outcome as potentially remote code execution. An attacker who can get a victim to render the malicious animation could achieve memory corruption with at least integrity and availability impact, and per ZDI possibly code execution. Anyone embedding or running rLottie at the affected commit is affected, including downstream applications that bundle the library for animation rendering. No public proof-of-concept or confirmed exploitation is known, and the issue is not in CISA KEV.

Do: Update rLottie to a build newer than commit 480a2ad0c5d2e45458c545b8213279e9e8b71e39 (latest upstream patched release) and rebuild any application that statically links or bundles the library. Until patched, avoid opening or rendering Lottie animation files (e.g., animated stickers) from untrusted sources, and check vendor advisories for apps embedding rLottie.

4.4
  • Samsung rLottie commit 480a2ad0c5d2e45458c545b8213279e9e8b71e39
unknown
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.

This source does not provide full text. Read it at zerodayinitiative.com.