Samsung Mobile Out-of-Bounds Write Vulnerability in libsavsac.so Allowing Arbitrary Code Execution

Vulnerability

A vulnerability allowing out-of-bounds write has been identified in the libsavsac.so library, in versions prior to the Samsung Security Maintenance Release (SMR) July 2026 Release 1. This vulnerability allows local attackers to execute arbitrary code. The issue arises from improper input validation, which has been addressed in the SMR July 2026 Release 1.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected device.

Remediation

Users can apply the Samsung Security Maintenance Release (SMR) July 2026 Release 1, which includes the patch for this vulnerability.

Added: Jul 10, 2026, 5:26 AM
Updated: Jul 10, 2026, 5:26 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
2.7
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.