Improper Input Validation in Samsung libsubextractor.so
CVE-2026-21088

6.9MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21088?

A security flaw has been identified in the libsubextractor.so library prior to SMR September 2026 Release 1, where improper input validation allows local attackers to exploit the loading of a subtitle frame. This vulnerability may enable attackers to write to out-of-bounds memory, potentially leading to arbitrary code execution or application crashes. It is crucial for users to update to the latest release to mitigate the risk associated with this issue.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.