VYPR
patchPublished Sep 9, 2026· Updated Sep 13, 2026· 1 source

Samsung One UI: 16 Vulnerabilities Disclosed, Including Critical Code Execution Flaws

Key findings • Two critical heap-based buffer overflow vulnerabilities in image decoders (CVE-2026-21095, CVE-2026-21096) allow remote code execution. • Multiple vulnerabilities across system…

Key findings

  • Two critical heap-based buffer overflow vulnerabilities in image decoders (CVE-2026-21095, CVE-2026-21096) allow remote code execution.
  • Multiple vulnerabilities across system components (SystemUI, KnoxVault, GalaxyDiagnostics) permit local privilege escalation or arbitrary code execution.
  • Improper access control flaws in SystemUI (CVE-2026-21100) and SettingsProvider (CVE-2026-21099) allow sensitive information access or arbitrary activity launches.
  • Path traversal vulnerabilities in GalaxyDiagnostics (CVE-2026-21103) and ImsService (CVE-2026-21092) enable unauthorized file access or creation.
  • The batch includes 16 CVEs disclosed on September 9, 2026, affecting One UI and various Samsung system components.
  • Fixes are available via the SMR Sep-2026 Release 1 and specific application updates.

On September 9, 2026, Samsung released a significant security update addressing a batch of 16 vulnerabilities affecting its One UI and various system components. These vulnerabilities, disclosed simultaneously, range in severity from Medium to Critical, with several allowing for local privilege escalation or arbitrary code execution. The disclosures highlight potential weaknesses in core system libraries and applications, underscoring the importance of timely patching for Samsung device users.

Several vulnerabilities stem from out-of-bounds write errors in critical system libraries. CVE-2026-21111 and CVE-2026-21100, for instance, involve out-of-bounds writes in libsthmbc.so and a JPEG decoder within libimagecodec.quram.so, respectively. These flaws, present in versions prior to One UI 8.5 and the SMR Sep-2026 Release 1, could allow local attackers to write out-of-bounds memory or execute arbitrary code. Similarly, CVE-2026-21105 describes a heap-based buffer overflow in the KnoxVault trustlet, also allowing local privileged attackers to execute arbitrary code.

Other vulnerabilities focus on improper access control and input validation. CVE-2026-21104, affecting the Collection component, and CVE-2026-21099, impacting SettingsProvider, allow local attackers to access sensitive information. CVE-2026-2100, a critical vulnerability in SystemUI, permits local attackers to launch arbitrary activities due to improper access control. Furthermore, CVE-2026-21094, a high-severity flaw in wpa_supplicant, involves improper input validation that could lead to out-of-bounds memory writes for adjacent attackers.

The batch also includes vulnerabilities related to file system access and manipulation. CVE-2026-21103 details a path traversal vulnerability in GalaxyDiagnostics, allowing physical attackers to access files with system privileges. CVE-2026-21092, an issue in ImsService, enables remote attackers to create image files with system server privileges through path traversal. Additionally, CVE-2026-21089 and CVE-2026-21088, both high-severity flaws in libsubextractor.so, involve improper input validation during style tag removal and subtitle frame loading, respectively, potentially allowing local attackers to write out-of-bounds memory.

Two critical vulnerabilities, CVE-2026-21095 and CVE-2026-21096, both related to heap-based buffer overflows in the DNG and JPEG decoders of libimagecodec.quram.so, respectively, pose a significant risk. These flaws, present prior to the SMR Sep-2026 Release 1, allow remote attackers to execute arbitrary code, representing the most severe threats within this disclosure batch.

Samsung has addressed these vulnerabilities through its Security Maintenance Release (SMR) for September 2026, with specific fixes also noted for One UI versions and individual application updates like Samsung Notes (version 4.4.45.5 and later). Users are strongly advised to ensure their devices are updated to the latest available software versions to mitigate these risks. The simultaneous disclosure of these numerous vulnerabilities emphasizes the need for proactive security management by both vendors and users in the mobile ecosystem.

The timely patching of these vulnerabilities is crucial for maintaining the security and integrity of Samsung devices. The range of affected components, from core system libraries to user-facing applications, highlights a broad attack surface. Users should prioritize applying the September 2026 security updates to protect against potential exploitation of these flaws.

Key findings from this batch include:

  • Two critical heap-based buffer overflow vulnerabilities in image decoders (CVE-2026-21095, CVE-2026-21096) allow remote code execution.
  • Multiple vulnerabilities across various system components (SystemUI, KnoxVault, GalaxyDiagnostics) permit local privilege escalation or arbitrary code execution.
  • Improper access control flaws in SystemUI (CVE-2026-21100) and SettingsProvider (CVE-2026-21099) allow sensitive information access or arbitrary activity launches.
  • Path traversal vulnerabilities in GalaxyDiagnostics (CVE-2026-21103) and ImsService (CVE-2026-21092) enable unauthorized file access or creation.
  • The batch includes 16 CVEs disclosed on the same day, September 9, 2026, affecting One UI and various Samsung system components.
  • Fixes are available via the SMR Sep-2026 Release 1 and specific application updates.
Synthesized by Vypr AI