NULL Pointer Dereference in Exynos Mobile and Wearable Processors by Samsung
CVE-2026-33970

3.5LOW

Key Information:

Vendor

Samsung

Vendor
CVE Published:
14 September 2026

What is CVE-2026-33970?

A vulnerability has been identified in the 5G baseband of Samsung's Exynos processors, including models such as Exynos 850, 1080, 2100, and others. This issue arises from a NULL Pointer Dereference that occurs when handling a specially crafted RRC Reconfiguration message. Exploitation of this vulnerability may disrupt normal operation, presenting risks to the security and stability of the devices utilizing these processors.

Affected Version(s)

Exynos 850 firmware 0 <= 2025-12-24

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.