CVE-2026-33964
Received Received - Intake

Untrusted Pointer Dereference in Samsung Mobile Processor Exynos Camera

Vulnerability report for CVE-2026-33964, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
samsung exynos_1580 *
samsung exynos_2500 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-822 The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an untrusted pointer dereference in the camera driver of Samsung Exynos 1580 and 2500 processors. It occurs when a malformed message is sent to the driver, potentially causing limited information disclosure or denial of service.

Detection Guidance

Detection of this vulnerability requires checking for untrusted pointer dereferences in the camera driver of Samsung Exynos 1580 or 2500 processors. Monitor system logs for camera driver crashes or unusual activity. Samsung may provide security patches or detection tools through their official support channels.

Impact Analysis

The vulnerability may allow attackers to access limited sensitive data or disrupt camera functionality on affected devices, leading to privacy risks or device malfunctions.

Compliance Impact

The vulnerability may impact compliance with GDPR and HIPAA due to potential information disclosure or denial of service in camera drivers of Samsung Exynos processors. Limited information disclosure could lead to unauthorized access to personal data, violating GDPR principles. Denial of service may disrupt critical operations, affecting HIPAA compliance for healthcare systems.

Mitigation Strategies

Apply the latest security patches or firmware updates provided by Samsung for Exynos 1580 and Exynos 2500 processors to address the untrusted pointer dereference issue in the camera driver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33964. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart