CVE-2026-33970: Samsung Exynos 850 Firmware
Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.
Affected products
- Samsung Exynos 850 Firmware: up to and including 2025-12-24
Published 2026-09-14. Last modified 2026-09-22.