VYPR
Vypr IntelligenceAI-generatedAug 12, 2026· 23 CVEs

Samsung Mobile: 23 Vulnerabilities Disclosed in August 2026 Patch Batch

Samsung Mobile addresses 23 vulnerabilities disclosed August 10-12, 2026, impacting rlottie, Smart Switch, and system libraries, with several rated High.

Key findings

  • 23 vulnerabilities disclosed for Samsung Mobile devices between August 10-12, 2026.
  • Multiple high-severity flaws found in codecs and system libraries, including buffer overflows.
  • Samsung Open Source rlottie and Smart Switch are among the affected components.
  • Vulnerabilities range from data access to arbitrary code execution and denial of service.
  • Patched in the SMR Aug-2026 Release 1 for most affected components.

Samsung Mobile released a security update on August 10, 2026, addressing a significant batch of 23 vulnerabilities discovered across its product ecosystem. The disclosures, spanning from August 10th to August 12th, 2026, highlight issues in various components including rlottie, Smart Switch, Galaxy Themes, and core system libraries. The vulnerabilities range in severity, with several rated as High, impacting the security and integrity of Samsung devices.

A notable cluster of vulnerabilities stems from the Samsung Open Source rlottie library, with CVE-2026-19588, CVE-2026-19587, CVE-2026-19518, and CVE-2026-19517 all related to improper input validation and resource management. These flaws could lead to buffer overflows and excessive memory allocation, potentially compromising device stability and security.

The Smart Switch application is affected by multiple medium-severity vulnerabilities, including CVE-2026-21083, CVE-2026-21080, CVE-2026-21079, and CVE-2026-21078. These issues involve improper input validation, cleartext storage of sensitive information, missing encryption, and insufficient data authenticity verification, all of which could expose user data to adjacent attackers.

Several high-severity vulnerabilities were identified in core system components and codecs. CVE-2026-21072, CVE-2026-21071, CVE-2026-21069, CVE-2026-21066, and CVE-2026-21065 relate to improper input validation and type conversion in various codecs (VC1, MPEG4, FLAC, QCELP) within libraries like libsavsvc.so and others, allowing local attackers to write out-of-bounds memory. Additionally, CVE-2026-21068, a stack-based buffer overflow in libril_sem.so, poses a risk of arbitrary code execution for privileged local attackers.

Other affected applications include Galaxy Themes (CVE-2026-21073), Samsung Message (CVE-2026-21070), Weaver (CVE-2026-21064), AppLock (CVE-2026-21063), SemClipboardService (CVE-2026-21062), Samsung Dialer (CVE-2026-21061), and Samsung Contacts (CVE-2026-21060, CVE-2026-21059, CVE-2026-21058). These vulnerabilities range from arbitrary activity launches and sensitive data access to authorization bypasses and file deletion.

The majority of these vulnerabilities were addressed in the SMR Aug-2026 Release 1, with specific version information provided for Smart Switch (prior to 3.7.72.6) and Galaxy Themes. Users are strongly advised to update their Samsung devices to the latest available security patch to mitigate these risks. The timely disclosure and patching of these vulnerabilities are crucial for maintaining the security posture of Samsung's mobile devices.

This extensive batch of vulnerabilities underscores the ongoing need for rigorous security auditing and prompt patching by device manufacturers. Users of Samsung mobile devices should prioritize applying the August 2026 security updates to protect against potential exploitation of these flaws. The wide range of affected components indicates a broad security effort by Samsung to address issues across its software and services.

AI-written article. Grounded in 23 CVE records listed below.