Skip to finding
interesting · Mobile — privilege

Samsung says a WSM use-after-free may execute code with Android system privilege.

Affects

Samsung Mobile devices running Android 14 through 17 with security software older than the October 2026 maintenance release.

The reported consequence crosses the application privilege boundary, but Samsung does not disclose the invoking IPC route, required permissions, or affected device coverage.

Detail and 1 source

We also do not know whether an ordinary application can reliably control execution after triggering the lifetime error.

Chain to watch
Invoke the vulnerable WSM service path from local code.→↓Trigger the use-after-free.→↓Attempt controlled execution with Android system privilege.→↓The reachable IPC entry point, permission checks, and reliability from an ordinary application are unknown.
Unverified chainDiff the WSM service around Samsung’s October release and reproduce the changed path under allocator instrumentation.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, October 6, 2026