CVE-2026-33957: Medium severity Samsung CustOS Driver vulnerability
Published Sep 14, 2026
·Updated
An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custosiwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.
Affected Software
1 affected component
Samsung CustOS Driver
Event History
Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of attacker access is required?
Exploitation requires local access and low privileges. No user interaction is required, but the attack complexity is rated high.
2
Which deployments are in scope?
The issue affects the CustOS Driver in Samsung Mobile Processor Exynos 1580. The provided information does not identify specific device models or software versions.
3
What is the assessed security impact?
The severity is medium, with a CVSS score of 4.2. The assessment indicates low confidentiality and availability impact, no integrity impact, and a changed scope.