NULL Pointer Dereference in Exynos Mobile and Wearable Processors by Samsung
CVE-2026-33970
3.5LOW
What is CVE-2026-33970?
A vulnerability has been identified in the 5G baseband of Samsung's Exynos processors, including models such as Exynos 850, 1080, 2100, and others. This issue arises from a NULL Pointer Dereference that occurs when handling a specially crafted RRC Reconfiguration message. Exploitation of this vulnerability may disrupt normal operation, presenting risks to the security and stability of the devices utilizing these processors.
Affected Version(s)
Exynos 850 firmware 0 <= 2025-12-24