CVE-2026-21018
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.
- Samsung Android
- = 14.0, 15.0, 16.0
- CVSS 4.0
- 6.8 MEDIUM
- CVSS 3.1
- 6.7 MEDIUM
- EPSS
- 0.2% (5th percentile)
- Weakness
- CWE-787
- NVD status
- Analyzed
- Published
- 2026-05-13
CVE-2026-21018 at NVD
5 known exploits for CVE-2026-21018
Proof-of-concept code and exploit modules indexed by Sploitus