CVE-2017-18655
Description
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a stack-based buffer overflow with resultant memory corruption in a trustlet. The Samsung IDs are SVE-2017-8889, SVE-2017-8891, and SVE-2017-8892 (August 2017).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stack-based buffer overflow in a Samsung trustlet on M(6.0) and N(7.x) devices causes memory corruption, leading to arbitrary code execution in the trustlet context.
Vulnerability
The vulnerability, tracked as CVE-2017-18655, is a stack-based buffer overflow in a trustlet on Samsung mobile devices running Android M (6.0) and N (7.x). The overflow results in memory corruption. This issue was addressed in Samsung's August 2017 security update (Samsung IDs SVE-2017-8889, SVE-2017-8891, and SVE-2017-8892). [1]
Exploitation
An attacker with local access to the device could potentially exploit this vulnerability. The exact attack vector and required privileges are not fully disclosed in the available references, but a stack-based buffer overflow in a trustlet suggests the attacker could send a crafted input to the trustlet component, leading to buffer overflow and memory corruption. [1]
Impact
Successful exploitation could result in memory corruption and potentially arbitrary code execution within the trustlet context. A trustlet is a trusted application running in ARM TrustZone, meaning compromise could allow the attacker to gain elevated privileges or access sensitive data protected by the trusted execution environment (TEE). [1]
Mitigation
Samsung released security updates in August 2017 to fix this vulnerability. Users should ensure their devices are running the latest Android security patch level. There is no known workaround besides applying the patch. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Samsung/mobile devicesdescription
- Range: M(6.0) and N(7.x)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- security.samsungmobile.com/securityUpdate.smsbmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.