Samsung Exynos: Nine Processor Vulnerabilities Disclosed Together on September 14, 2026
Nine vulnerabilities affecting various Samsung Exynos processors were disclosed on September 14, 2026, spanning multiple components and ranging in severity from Low to High.

Key findings
- Nine vulnerabilities affecting Samsung Exynos processors were disclosed on September 14, 2026.
- Vulnerabilities span multiple components including camera, DPU, MFC, and drivers, with severities ranging from Low to High.
- High-severity flaw CVE-2026-23789 in the MFC encoder driver involves a double-free vulnerability.
- Medium-severity DPU driver flaws (CVE-2026-23791, CVE-2026-23790, CVE-2026-23788) can lead to memory corruption and privilege escalation.
- Low-to-medium severity issues include information disclosure, denial of service, and kernel memory corruption.
- A wide range of Exynos processors, from mobile to automotive and wearable, are affected.
On September 14, 2026, a batch of nine vulnerabilities affecting various Samsung Exynos processors was disclosed. These vulnerabilities span multiple components including the camera, DPU, MFC, and buffer queue drivers, with severities ranging from Low to High. The disclosures occurred within a six-hour window, indicating a coordinated release of security information. These flaws could lead to kernel memory corruption, information disclosure, denial of service, and privilege escalation, posing a significant risk to users of affected Samsung devices.
Several vulnerabilities are related to memory corruption due to improper input validation or pointer dereferencing. CVE-2026-33964, a medium-severity issue in the camera driver, involves an untrusted pointer dereference that can lead to limited information disclosure or denial of service. Similarly, CVE-2026-23793, a low-severity flaw in the camera GDC driver, can result in kernel memory corruption.
A cluster of medium-severity vulnerabilities affects the DPU (Display Processing Unit) driver. CVE-2026-23791 describes an out-of-bounds write leading to kernel memory corruption and potential privilege escalation. CVE-2026-23790, also in the DPU driver, is a double-free vulnerability that can result in kernel memory corruption and a use-after-free condition. CVE-2026-23788, a heap overflow in the Exynos DRM HDR driver, can cause kernel memory corruption and a system crash.
The MFC (Multimedia Codec Framework) encoder driver is also impacted. CVE-2026-23789, a high-severity vulnerability, is a double-free issue stemming from improper cleanup of DMA buffer references during error handling, potentially leading to severe system instability or compromise.
Other vulnerabilities include CVE-2026-33957, a medium-severity issue in the CustOS Driver that allows out-of-bounds read and write operations, and CVE-2024-53922, a medium-severity denial-of-service vulnerability in the buffer queue driver due to a missing length check. CVE-2023-37366, a low-severity vulnerability, affects a wide range of Exynos processors and modems, though its specific impact is not detailed in the provided information.
The broad range of affected Exynos processors, from mobile to automotive and wearable variants, highlights the widespread potential impact of these vulnerabilities. Users of Samsung devices powered by these Exynos chipsets should remain vigilant for security updates from Samsung. The coordinated disclosure of these nine CVEs on the same day underscores the importance of prompt patching and security awareness for these complex system-on-chips.
The vulnerabilities disclosed affect various Samsung Exynos processors, including but not limited to Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, 5123, 5300, 1580, 2500, 1480, 2400, 1680, 2600, W930, W1000, and Exynos Auto T5123, V7, V9, V920. The specific impact and affected versions vary per CVE.
Given the nature of these vulnerabilities, which primarily involve memory corruption and driver-level exploits, prompt patching by Samsung is crucial. Users should ensure their devices are updated to the latest available firmware to mitigate these risks. The coordinated disclosure suggests a significant security event for the Exynos ecosystem.
Key findings include:
- Nine vulnerabilities affecting Samsung Exynos processors were disclosed on September 14, 2026.
- Vulnerabilities span multiple components including camera, DPU, MFC, and drivers.
- High-severity flaw CVE-2026-23789 in the MFC encoder driver involves a double-free vulnerability.
- Medium-severity DPU driver flaws (CVE-2026-23791, CVE-2026-23790, CVE-2026-23788) can lead to memory corruption and privilege escalation.
- Low-to-medium severity issues include information disclosure, denial of service, and kernel memory corruption.
- A wide range of Exynos processors, from mobile to automotive and wearable, are affected.