CVE-2026-33962
Received Received - Intake

Wi-Fi Out-of-Bounds Read in Samsung Exynos Processors

Vulnerability report for CVE-2026-33962, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
samsung exynos_850 *
samsung exynos_1280 *
samsung exynos_1330 *
samsung exynos_1380 *
samsung exynos_1480 *
samsung exynos_2400 *
samsung w920 *
samsung w930 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read issue in the Wi-Fi module of certain Samsung Exynos chipsets. It occurs when a malformed Netlink command is processed, causing the system to read memory outside its intended bounds. This can lead to unauthorized access to sensitive information stored in memory.

Detection Guidance

Detection requires checking for affected Samsung Exynos chipsets. Use system commands like 'uname -a' or 'cat /proc/version' to identify the processor model. Compare the output against the list of affected chipsets (Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, W930).

Inspect Wi-Fi module logs for unusual activity or errors related to netlink commands. Check for kernel messages with 'dmesg | grep -i netlink' or 'journalctl -k | grep -i wifi'.

Impact Analysis

If exploited, this vulnerability could allow an attacker to access sensitive data stored in memory, such as passwords or encryption keys. However, the attack requires local access to the device and a high level of technical skill due to the complexity of the exploit.

Compliance Impact

This vulnerability could potentially lead to information leakage, which may impact compliance with data protection regulations like GDPR and HIPAA by exposing sensitive user data. However, the provided context does not specify direct compliance implications or affected systems handling regulated data.

Mitigation Strategies

Apply the latest security patches from Samsung for the affected chipsets. Disable Wi-Fi if not in use or restrict network access until patched. Monitor official Samsung security updates for firmware fixes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33962. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart