Samsung Galaxy: a crafted image can run code without a single tap

Samsung shipped its September security package on September 8. Called SMR Sep-2026 Release 1, it includes 90 fixes, and Samsung rates two of them critical. Both are in the same component, the code that decodes images on Galaxy phones.
The two entries are SVE-2026-3247 and SVE-2026-3282, tracked publicly as CVE-2026-21095 and CVE-2026-21096. The first affects the DNG decoder, the second the JPEG decoder. Both are in libimagecodec.quram.so, the library Samsung uses to process images. DNG is a raw photo format that many cameras and phones produce. Samsung describes each one as a heap-based buffer overflow that "allows remote attackers to execute arbitrary code." Android 14, 15, 16 and 17 are affected.
Why this is more than a routine patch line
The CVE record, which Samsung filed itself, carries a CVSS score of 9.2 out of 10. The vector matters more than the number. It includes UI:N, meaning an attack requires no action from the user. No tap on a file, no confirmation. The device only has to process a malformed image. The same vector also includes AT:P, so additional conditions have to be met before an attack works.
Brendon Tiszka and Mateusz Jurczyk of Google Project Zero found both flaws, and Samsung credits them in the acknowledgements section of its bulletin. Both entries are marked "Privately disclosed," so there are no reports of attacks. The fix itself is a small one. Samsung says only that it adds proper input validation.
Attackers abused the same library in 2025
This is not the first time that part of the system has caused problems. In 2025, attackers used libimagecodec.quram.so to deliver commercial spyware called Landfall. Researchers at Palo Alto Networks Unit 42 documented how malformed DNG files sent over WhatsApp compromised phones without the victim clicking anything. Samsung closed that flaw, CVE-2025-21042, in April 2025, and the U.S. cybersecurity agency CISA added it to its catalog of known exploited vulnerabilities in November. Known targets were in Iraq, Iran, Turkey and Morocco.
The flaws Samsung just patched are separate bugs. They affect the same component and the same file format, which shows the decoder remains an attack surface.
How to check your patch level
Open Settings, then Software update, then Software information, and look at the Android security patch level. If the date is from September 2026, your phone already has the package. If it shows August or earlier, tap Download and install.
Samsung sends these packages to its current flagships first, and older devices follow in the weeks after. That pattern showed up with the July update as well. We also looked at Samsung Internet to see which parts of the system the monthly patch never reaches.
Of the 90 fixes, 58 come from Google's Android bulletin, 18 of them critical and 40 rated high. Another fix comes from Samsung Semiconductor, and the remaining 31 come from Samsung Mobile. Our report on the June bulletin explains how the monthly Android package is put together and why individual flaws still take a long time to reach phones.





