RRC Handling Vulnerability in Samsung Mobile Processors and Modems
CVE-2026-23792

4MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
14 September 2026

What is CVE-2026-23792?

A vulnerability has been identified in the NR RRC component of various Samsung Mobile Processors and Modems. This issue arises from improper handling of unauthenticated downlink RRC Setup messages, potentially leading to a baseband crash. This flaw could disrupt the functionality of affected devices, making it essential for users to stay informed and apply any available security updates to mitigate risks.

Affected Version(s)

Exynos 1080 firmware 0 <= 2025-10-22

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.