CVE-2026-33964: Medium severity Samsung Samsung Exynos 1580 vulnerability
Published Sep 14, 2026
·Updated
An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.
Affected Software
2 affected components
Samsung Samsung Exynos 1580
Samsung Samsung Exynos 2500
Event History
Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are in scope?
The affected hardware listed is Samsung Exynos 1580 and Samsung Exynos 2500 mobile processors. The issue is in the camera component.
2
What access does an attacker need?
Exploitation requires local access and low privileges, with no user interaction required. The attacker must be able to send a malformed message to the camera driver.
3
What is the expected impact of successful exploitation?
Successful exploitation can cause limited information disclosure or denial of service. The CVSS vector indicates availability impact is high, confidentiality impact is low, and integrity impact is not affected.