Out-of-Bounds Write Vulnerability in Samsung Open Source Escargot for Linux x86-64
CVE-2026-86315

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86315?

An out-of-bounds write vulnerability in Samsung's Open Source Escargot on Linux x86-64 platforms allows an attacker to potentially corrupt native memory. This can be exploited via specially crafted JavaScript, where a crafted class definition's instance initialization entry count exceeds the UINT16_MAX limit, leading to a crash of the host process. Users of affected versions should take immediate precautions to mitigate this risk.

Affected Version(s)

Escargot 5dc93606abd42b859045add05d704a038e197359

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

p4p3r of 싸이버원
.