Out-of-Bounds Memory Vulnerability in VC1 Codec for Samsung Products
CVE-2026-21069

5.1MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
10 August 2026

What is CVE-2026-21069?

A vulnerability present in the VC1 codec within libsavsvc.so prior to the SMR Aug-2026 Release 1 allows local attackers to perform out-of-bounds memory writes. This issue arises from an error in the conversion between numeric types, potentially enabling unauthorized access to system memory and manipulation of application behavior.

Affected Version(s)

Samsung Mobile Devices SMR Aug-2026 Release in Android 14, 15, 16

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.