VYPR
Unrated severityNVD Advisory· Published Mar 13, 2023· Updated Mar 3, 2025

CVE-2023-26072

CVE-2023-26072

Description

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the Emergency number list.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Heap buffer overflow in Samsung Exynos 5G MM codec when decoding Emergency number list, exploitable by malicious network operator or local attacker.

Vulnerability

A heap-based buffer overflow exists in the 5G Mobility Management (MM) message codec of Samsung Exynos chipsets including Exynos 850, 980, 1080, 1280, 2200, Modem 5123, 5300, and Auto T5123 [1]. The vulnerability occurs due to insufficient parameter validation when decoding the Emergency number list from a NAS message. This issue is one of fourteen less severe vulnerabilities reported by Project Zero [4].

Exploitation

Exploitation requires either a malicious mobile network operator (MMO) that can inject crafted 5G NAS messages, or an attacker with local access to the device. The attacker crafts a malformed Emergency number list that triggers the heap overflow during decoding. No user interaction is needed when the attacker controls the network; local access may involve a malicious app [4].

Impact

Successful exploitation leads to a heap buffer overflow in the baseband processor, potentially allowing an attacker to corrupt memory and achieve arbitrary code execution at the baseband level. This compromises the confidentiality, integrity, and availability of baseband communications, though the attack surface is limited compared to the more severe internet-to-baseband RCE vulnerabilities [4].

Mitigation

Samsung has released security updates for affected chipsets; contact the device manufacturer for specific patch availability. As of March 2023, Google Pixel devices had received fixes for related vulnerabilities [4]. Defenders should consult the Samsung Product Security Update page [1] for the latest advisory. Users with affected devices are advised to apply updates as soon as possible.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.