CVE-2026-0146
Samsung · MFC Core (Multi-Format Codec)
A memory-related vulnerability exists within the `mfc_core_get_dec_metadata_sei_nal` function of the Samsung MFC core, potentially allowing for system-level impact.
Executive summary
An unauthenticated attacker may exploit a memory-handling vulnerability in the Samsung MFC core to trigger a crash or potentially execute arbitrary code.
Vulnerability
This is a memory-related vulnerability located in the mfc_core_get_dec_metadata_sei_nal function of the mfc_core_reg_api. It involves improper handling of SEI (Supplemental Enhancement Information) NAL units during video decoding processes.
Business impact
With a CVSS score of 8.8, this vulnerability poses a severe risk to mobile and embedded devices utilizing the Samsung MFC codec. Exploitation could lead to unauthorized code execution, system crashes, or data compromise, particularly in environments where video processing is a primary attack vector.
Remediation
Immediate Action: Update all affected firmware and software components to the latest version released by the device manufacturer or vendor.
Proactive Monitoring: Monitor system logs for frequent crashes or unusual reboots of the media processing subsystem.
Compensating Controls: Avoid processing untrusted or malformed media files from unknown sources, and ensure that the device's security patches are fully up to date.
Exploitation status
Public Exploit Available: false
Analyst recommendation
This vulnerability represents a significant risk to device security. Users and administrators must verify that their devices receive the latest manufacturer updates to mitigate the risk of malicious media-based exploitation.