CVE-2026-0146

Samsung · MFC Core (Multi-Format Codec)

A memory-related vulnerability exists within the `mfc_core_get_dec_metadata_sei_nal` function of the Samsung MFC core, potentially allowing for system-level impact.

Executive summary

An unauthenticated attacker may exploit a memory-handling vulnerability in the Samsung MFC core to trigger a crash or potentially execute arbitrary code.

Vulnerability

This is a memory-related vulnerability located in the mfc_core_get_dec_metadata_sei_nal function of the mfc_core_reg_api. It involves improper handling of SEI (Supplemental Enhancement Information) NAL units during video decoding processes.

Business impact

With a CVSS score of 8.8, this vulnerability poses a severe risk to mobile and embedded devices utilizing the Samsung MFC codec. Exploitation could lead to unauthorized code execution, system crashes, or data compromise, particularly in environments where video processing is a primary attack vector.

Remediation

Immediate Action: Update all affected firmware and software components to the latest version released by the device manufacturer or vendor.

Proactive Monitoring: Monitor system logs for frequent crashes or unusual reboots of the media processing subsystem.

Compensating Controls: Avoid processing untrusted or malformed media files from unknown sources, and ensure that the device's security patches are fully up to date.

Exploitation status

Public Exploit Available: false

Analyst recommendation

This vulnerability represents a significant risk to device security. Users and administrators must verify that their devices receive the latest manufacturer updates to mitigate the risk of malicious media-based exploitation.