Samsung libsthmbc
cpe:2.3:o:samsung:samsung_mobile:*:*:*:*:*:*:*
- >= 12, <= 14
A high-severity out-of-bounds write vulnerability has been identified in the libsthmbc.so library, present in Samsung devices running Android 12, 13, or 14, prior to the January 2025 Security Maintenance Release. This vulnerability allows local attackers to execute arbitrary code with elevated privileges. The issue arises from improper handling of the buffer that stores decoded video frames, creating an opportunity for exploitation. User interaction is required to trigger this vulnerability.
Exploitation of this vulnerability could lead to arbitrary code execution with elevated privileges on the affected device.
Users can update to the January 2025 Security Maintenance Release to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.