Skip to finding
§
High
Zero-click — Samsung Galaxy
Provisional
CVE-2026-21095

A remotely delivered DNG or JPEG can execute code on affected Samsung Galaxy devices without user interaction.

Both paths begin with heap overflows in Samsung's libimagecodec.quram.so decoders.

Affects

Samsung Mobile Devices using Samsung's proprietary image-decoding library on Android 14 through Android 17.

What it enables

Remote code execution during DNG or JPEG image decoding without user interaction

Attacker remotely supplies a crafted DNG or JPEG through a content-delivery path that reaches the Samsung device→↓The device processes the image with the corresponding libimagecodec.quram.so decoder without user interaction→↓Malformed decoder input causes a heap-based buffer overflow→↓The overflow permits arbitrary code execution on the device
Why this matters

The Samsung records require neither privileges nor user interaction, moving these decoder bugs from memory corruption to a passive remote code-execution capability.

Detail, proof-of-concept code and 4 sources
Required access

Network delivery through a path that causes the device to process a crafted image; Samsung's CNA records require no privileges or user interaction but leave an additional attack requirement unspecified.

Affected versions

Samsung Mobile Devices before SMR Sep-2026 Release 1 running Android 14, Samsung Mobile Devices before SMR Sep-2026 Release 1 running Android 15, Samsung Mobile Devices before SMR Sep-2026 Release 1 running Android 16, Samsung Mobile Devices before SMR Sep-2026 Release 1 running Android 17

An attacker sends crafted image data through a path that causes the device to invoke the DNG or JPEG decoder; the resulting heap overflow permits code execution during processing.

Samsung says the flaws were addressed in a shipped maintenance release.

We still do not know the concrete delivery transport or the additional attack requirement recorded by Samsung, and no public trigger artifact was identified.

Evidence
Samsung's bulletin identifies both heap overflows, affected Android versions, remote code execution and the shipped maintenance releaseSamsung-authored CNA records classify both as network-reachable, unauthenticated and requiring no user interaction, with attack requirements presentNo public trigger artifact or concrete delivery transport was found
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026