A remotely delivered DNG or JPEG can execute code on affected Samsung Galaxy devices without user interaction.
Both paths begin with heap overflows in Samsung's libimagecodec.quram.so decoders.
Samsung Mobile Devices using Samsung's proprietary image-decoding library on Android 14 through Android 17.
Remote code execution during DNG or JPEG image decoding without user interaction
The Samsung records require neither privileges nor user interaction, moving these decoder bugs from memory corruption to a passive remote code-execution capability.
Detail, proof-of-concept code and 4 sources
An attacker sends crafted image data through a path that causes the device to invoke the DNG or JPEG decoder; the resulting heap overflow permits code execution during processing.
Samsung says the flaws were addressed in a shipped maintenance release.
We still do not know the concrete delivery transport or the additional attack requirement recorded by Samsung, and no public trigger artifact was identified.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Reaches end-of-life hardware
- No
No public patch diff or vendor test corpus was available for determining how the fixed decoders handle the original triggering images.