Double-Free Vulnerability in Samsung Exynos Mobile Processors
CVE-2026-23789

7.8HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
14 September 2026

What is CVE-2026-23789?

A double-free vulnerability exists in the MFC encoder driver of Samsung's Exynos mobile and wearable processors, caused by improper cleanup of dma_buf references during error handling. This flaw may lead to kernel memory corruption, enabling potential attackers to execute arbitrary code. Affected products are widely utilized in mobile and wearable devices, necessitating prompt security updates to mitigate the risk.

Affected Version(s)

Exynos 850 firmware 0 <= 2025-12-23

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.