Input Validation Flaw in Samsung Products Allows Memory Manipulation
CVE-2026-21089

6.9MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21089?

An improper input validation flaw exists in libsubextractor.so before the SMR September 2026 Release 1. This vulnerability allows local attackers to exploit the system by writing out-of-bounds memory, potentially leading to system instability or unauthorized code execution. It is crucial for users of affected Samsung products to apply the necessary updates to mitigate these risks and protect their systems.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.