ZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
ZDI discloses CVE-2026-21045, a heap buffer overflow in Samsung Galaxy S25 TIFF processing enabling RCE via malicious files or pages.
ZDI-26-529 describes a heap-based buffer overflow in Samsung Galaxy S25 TIFF file processing that allows remote attackers to execute arbitrary code. User interaction is required, as the target must visit a malicious page or open a malicious file. ZDI assigned a CVSS score of 8.8, tracked as CVE-2026-21045.