Samsung Mobile: Four Medium-Severity Vulnerabilities in mTower and rlottie Disclosed
Samsung Mobile disclosed four medium-severity vulnerabilities in its open-source mTower and rlottie components on September 1, 2026.

Key findings
- Four medium-severity vulnerabilities disclosed by Samsung Mobile on September 1, 2026.
- Vulnerabilities affect Samsung's open-source components: mTower and rlottie.
- Issues include untrusted pointer dereferences, NULL pointer dereference, and uncontrolled recursion.
- All vulnerabilities have a CVSSv3 score of 5.5.
- Affected versions are prior to specific commit hashes in mTower and rlottie.
On September 1, 2026, Samsung Mobile disclosed four medium-severity vulnerabilities affecting its open-source components, mTower and rlottie. The vulnerabilities, disclosed within a 24-hour window, include untrusted pointer dereferences, a NULL pointer dereference, and uncontrolled recursion. These issues could allow for pointer manipulation and the processing of serialized data with nested payloads.
The mTower component is affected by three vulnerabilities: CVE-2026-10420, CVE-2026-82927, and CVE-2026-82926. All three are described as untrusted pointer dereferences or NULL pointer dereferences that allow for pointer manipulation. These issues affect versions of mTower before specific commit hashes: 102d3dc75cf8e58e68e4bea54ae3c803992c91be for CVE-2026-10420, 06994e303637512e39062f3e037c222e8448e57e for CVE-2026-82927, and afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a for CVE-2026-82926.
The fourth vulnerability, CVE-2026-82797, affects the rlottie component. This vulnerability is an uncontrolled recursion issue that allows for serialized data with nested payloads. It affects versions of rlottie before commit hash 8de0d9e6ca80ffef654965505981727b9fa06a51.
All disclosed vulnerabilities have a CVSSv3 score of 5.5, categorizing them as medium severity. No information regarding active exploitation or specific threat actors has been reported in relation to this batch of vulnerabilities.
Samsung's open-source components are integral to various mobile functionalities. Users are advised to ensure their systems are updated to versions that incorporate the mentioned fixes, specifically those that include the commits referenced in the vulnerability descriptions. Staying updated is crucial for mitigating risks associated with pointer manipulation and uncontrolled recursion vulnerabilities.