SamsungCVE-2026-18772
Improperly controlled sequential memory allocation vulnerability in Samsung...
Medium6.5CVE-2026-18772 · Published Aug 4, 2026 · updated Sep 23, 2026
Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-1325
More Samsung advisories
All Samsung| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Samsung: improper input validation | Medium5.1 | No fix yet |
| Aug 10 | Samsung SemClipboardService: local attacker could access clipboard data | Medium4.8 | No fix yet |
| Aug 10 | Samsung Dialer: improper input validation | Medium6.0 | No fix yet |
| Aug 10 | Samsung Contacts: improper input validation | Medium6.7 | No fix yet |
| Aug 10 | Samsung Contacts: exported component | Medium6.9 | No fix yet |
| Aug 10 | Samsung Contacts: improper input validation | Medium6.9 | No fix yet |