CVE-2026-33957: Samsung Exynos 1580 Firmware

Medium severity, CVSS 4.2. EPSS: 0.1% chance of exploitation in the next 30 days.

An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.

Affected products

  • Samsung Exynos 1580 Firmware: up to and including 2026-01-07

Published 2026-09-14. Last modified 2026-09-22.