Out of Range Operator Code Lookup Issue in Samsung ONE
CVE-2026-6840

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-6840?

A vulnerability exists in Samsung ONE where missing bounds validation allows for out of range operator-code lookup during the model loading process. This flaw can lead to unintended behavior and potential security risks when operating with specific model configurations. Users are advised to update to version 1.30.0 or later to mitigate this issue.

Affected Version(s)

ONE 1.30.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.