CVE-2023-26072
Description
An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the Emergency number list.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Heap buffer overflow in Samsung Exynos 5G MM codec when decoding Emergency number list, exploitable by malicious network operator or local attacker.
Vulnerability
A heap-based buffer overflow exists in the 5G Mobility Management (MM) message codec of Samsung Exynos chipsets including Exynos 850, 980, 1080, 1280, 2200, Modem 5123, 5300, and Auto T5123 [1]. The vulnerability occurs due to insufficient parameter validation when decoding the Emergency number list from a NAS message. This issue is one of fourteen less severe vulnerabilities reported by Project Zero [4].
Exploitation
Exploitation requires either a malicious mobile network operator (MMO) that can inject crafted 5G NAS messages, or an attacker with local access to the device. The attacker crafts a malformed Emergency number list that triggers the heap overflow during decoding. No user interaction is needed when the attacker controls the network; local access may involve a malicious app [4].
Impact
Successful exploitation leads to a heap buffer overflow in the baseband processor, potentially allowing an attacker to corrupt memory and achieve arbitrary code execution at the baseband level. This compromises the confidentiality, integrity, and availability of baseband communications, though the attack surface is limited compared to the more severe internet-to-baseband RCE vulnerabilities [4].
Mitigation
Samsung has released security updates for affected chipsets; contact the device manufacturer for specific patch availability. As of March 2023, Google Pixel devices had received fixes for related vulnerabilities [4]. Defenders should consult the Samsung Product Security Update page [1] for the latest advisory. Users with affected devices are advised to apply updates as soon as possible.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Samsung/Mobile Chipset and Baseband Modem Chipset for Exynosdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- packetstormsecurity.com/files/171378/Shannon-Baseband-NrmmMsgCodec-Emergency-Number-List-Heap-Buffer-Overflow.htmlmitre
- bugs.chromium.org/p/project-zero/issues/detailmitre
- googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.htmlmitre
- semiconductor.samsung.com/processor/mobile-processor/mitre
- semiconductor.samsung.com/processor/modem/mitre
- semiconductor.samsung.com/support/quality-support/product-security-updates/mitre
News mentions
0No linked articles in our index yet.