Out-of-Bounds Write Vulnerability in libimagecodec.media.quram.so, Affected by Samsung
CVE-2026-21045
Key Information:
- Vendor
Samsung
- Status
- Vendor
- CVE Published:
- 10 July 2026
Badges
What is CVE-2026-21045?
An out-of-bounds write vulnerability exists in the TIFF parsing component of libimagecodec.media.quram.so. This flaw allows remote attackers to exploit the system by writing to areas of memory that are not allocated for that purpose, potentially leading to arbitrary code execution or crashes. Users are advised to update to the latest version provided in the SMR July 2026 Release 1 to mitigate this security risk.
Affected Version(s)
Samsung Mobile Devices SMR Jul-2026 Release in Android 14, 15, 16
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved