CVE-2026-21047

8.3

Samsung · Mobile Devices

Samsung mobile devices are vulnerable to an out-of-bounds write in the ImsService, which may allow a remote attacker to execute arbitrary code.

Executive summary

A critical out-of-bounds write vulnerability in the Samsung ImsService component could allow remote attackers to execute arbitrary code on affected mobile devices.

Vulnerability

This is an out-of-bounds write vulnerability occurring within the ImsService component, which handles IP Multimedia Subsystem functions. The flaw allows an unauthenticated remote attacker to write data outside of designated memory buffers, potentially resulting in arbitrary code execution.

Business impact

The vulnerability carries a CVSS score of 8.3, indicating high severity. Successful exploitation could lead to full system compromise, unauthorized access to sensitive user data, and the potential for persistent malware installation on the device. Organizations relying on these devices for mobile operations should treat this as a significant security risk to their mobile fleet.

Remediation

Immediate Action: Update all affected Samsung devices to the SMR Jul-2026 Release 1 or later to apply the necessary memory validation logic.

Proactive Monitoring: Security teams should review device access logs and monitor for unexpected service crashes or anomalous behavior related to the ImsService.

Compensating Controls: Ensure device security policies are enforced via Mobile Device Management (MDM) solutions to restrict network exposure where possible.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the potential for remote code execution, it is imperative that administrators prioritize the deployment of the SMR Jul-2026 Release 1 across all managed Samsung assets. Prompt patching is the only effective method to eliminate the risk posed by this memory corruption vulnerability.

More Samsung CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section