VYPR
Unrated severityNVD Advisory· Published Apr 7, 2020· Updated Aug 5, 2024

CVE-2017-18685

CVE-2017-18685

Description

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The InputMethod application can cause a system crash via a malformed serializable object in an Intent. The Samsung ID is SVE-2016-7123 (February 2017).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A malformed serializable object in an Intent causes a system crash via the InputMethod application on Samsung devices running Android KK(4.4), L(5.0/5.1), and M(6.0).

Vulnerability

The InputMethod application on Samsung mobile devices with Android versions KitKat (4.4), Lollipop (5.0/5.1), and Marshmallow (6.0) is vulnerable to a denial-of-service condition. An issue exists where processing a malformed serializable object delivered through an Intent can trigger a system crash. The vulnerability is identified by Samsung ID SVE-2016-7123 (February 2017) [1].

Exploitation

An attacker can exploit this vulnerability by crafting a malicious Intent containing a malformed serializable object and sending it to the InputMethod application. No special permissions or user interaction beyond normal Intent handling is required; the malformed data can be delivered via any application that can send Intents to the InputMethod component. The processing of the malformed object leads to an unhandled exception or memory corruption that causes the system to crash.

Impact

Successful exploitation results in a denial of service, causing the affected device to crash and potentially restart. This disrupts all device operations until the system recovers. The impact is limited to availability; there is no evidence of privilege escalation or data compromise in the available references.

Mitigation

Samsung has not publicly disclosed a specific security update for this issue on its Samsung Mobile Security website [1]. Users are advised to apply any available firmware updates provided by Samsung or their carrier. If the devices are no longer receiving updates, the vulnerability remains unpatched and no workaround is documented.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.