Heap Overflow Vulnerability in Samsung Exynos Mobile Processors
CVE-2026-23786

2.8LOW

Key Information:

Vendor

Samsung

Vendor
CVE Published:
14 September 2026

What is CVE-2026-23786?

A vulnerability has been identified within the Data Path Unit (DPU) of several Samsung Exynos Mobile Processors, including the Exynos 1280, 2200, and others. This vulnerability arises from a Time-of-Check to Time-of-Use (TOCTOU) race condition within the Exynos DRM HDR Driver, which can lead to a heap overflow. This overflow has the potential to cause unexpected behavior, including crashes in the kernel, which could compromise the stability of affected devices. Users are advised to monitor updates from Samsung and secure their devices accordingly.

Affected Version(s)

Exynos 1280 firmware 0 <= 2025-12-24

References

CVSS V3.1

Score:
2.8
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.