Stack-based Buffer Overflow in Samsung Opensource rLottie
CVE-2026-91826

4.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91826?

A stack-based buffer overflow vulnerability in Samsung's Opensource rLottie library allows attackers to exploit flaws in the rendering of crafted vector animations. This can lead to memory corruption, compromising system integrity and security. The issue specifically affects version 480a2ad0c5d2e45458c545b8213279e9e8b71e39, emphasizing the need for users to secure their applications relying on this library against potential exploits.

Affected Version(s)

rLottie 480a2ad0c5d2e45458c545b8213279e9e8b71e39

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anonymous working with TrendAI Zero Day Initiative
.