ZDI-CAN-29432: ZDI-26-529: Samsung Galaxy S25 TIFF File Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S25 devices. User interaction may be required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-21045.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29432?
ZDI-CAN-29432 has been assigned a CVSS risk score of 82, indicating a high severity level.
How do I fix ZDI-CAN-29432?
To mitigate ZDI-CAN-29432, ensure that your Samsung Galaxy S25 device is updated with the latest security patches provided by Samsung.
What type of vulnerability is ZDI-CAN-29432?
ZDI-CAN-29432 is a heap-based buffer overflow vulnerability that can lead to remote code execution.
Do I need to interact with the device to exploit ZDI-CAN-29432?
Yes, user interaction is typically required for exploiting ZDI-CAN-29432, such as visiting a malicious web page or opening a malicious file.
Which devices are affected by ZDI-CAN-29432?
ZDI-CAN-29432 specifically affects the Samsung Galaxy S25 device.