Heap-Based Buffer Overflow in libimagecodec.quram.so Affects Samsung Products
CVE-2026-21095
9.2CRITICAL
What is CVE-2026-21095?
The vulnerability in the DNG decoder of libimagecodec.quram.so allows remote attackers to exploit a heap-based buffer overflow. This flaw can lead to the execution of arbitrary code, posing significant security risks to affected devices. Users are encouraged to apply the SMR Sep-2026 Release 1 update to mitigate any potential threats.
Affected Version(s)
Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17