Improper Input Validation in VC1 Codec in Samsung Products
CVE-2026-21072
5.1MEDIUM
What is CVE-2026-21072?
Improper input validation in the VC1 codec within the libsavsvc.so library for Samsung products prior to the SMR Aug-2026 Release 1 enables local attackers to exploit out-of-bounds memory write vulnerabilities. This flaw may lead to unauthorized manipulation of memory, potentially resulting in system instability or exploitation of sensitive data.
Affected Version(s)
Samsung Mobile Devices SMR Aug-2026 Release in Android 14, 15, 16