Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT
Abandoned AOSP OpenCORE AAC decoder has out-of-bounds-write and wild-pointer flaws reachable from attacker-controlled frames, unpatched in Samsung TizenRT.
The OpenCORE AAC decoder in AOSP's abandoned external/opencore tree contains memory-safety defects of the out-of-bounds-write and wild-pointer class. The code is still vendored and built by multiple projects, most notably Samsung's widely deployed TizenRT embedded RTOS. The defects are reachable from untrusted media because an AAC frame is attacker-controlled. The researcher is requesting a CVE ID for the issue.
ZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
ZDI discloses CVE-2026-21045, a heap buffer overflow in Samsung Galaxy S25 TIFF processing enabling RCE via malicious files or pages.
ZDI-26-529 describes a heap-based buffer overflow in Samsung Galaxy S25 TIFF file processing that allows remote attackers to execute arbitrary code. User interaction is required, as the target must visit a malicious page or open a malicious file. ZDI assigned a CVSS score of 8.8, tracked as CVE-2026-21045.