Heap-based Buffer Overflow in Samsung Mobile JPEG Decoder
CVE-2026-21096

9.2CRITICAL

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21096?

A heap-based buffer overflow vulnerability exists in the JPEG decoder of libimagecodec.quram.so prior to the SMR Sep-2026 Release 1. This flaw could potentially allow remote attackers to execute arbitrary code on affected systems, posing significant security risks. It is essential for users to upgrade to the latest release to mitigate this issue.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.