Use-After-Free Vulnerability in Samsung Exynos Mobile Processors
CVE-2026-23787
4.2MEDIUM
What is CVE-2026-23787?
A vulnerability has been identified in the Samsung Exynos mobile processors, specifically within the Digital Processing Unit (DPU). The issue arises from a use-after-free condition in the Exynos Digital Rights Management (DRM) High Dynamic Range (HDR) driver, which occurs due to inadequate cleanup procedures following a vmap failure. This mismanagement can result in kernel crashes, impacting device stability and compromising user security.
Affected Version(s)
Exynos 1280 firmware 0 <= 2025-12-24