CVE-2026-21045 is an out-of-bounds write vulnerability in the TIFF parsing logic of Samsung Mobile's libimagecodec.media.quram.so library. The flaw affects Samsung Mobile devices prior to SMR Jul-2026 Release 1, including affected Android 14, 15, and 16 builds before that release. Improper handling of TIFF-formatted input can cause writes beyond the bounds of allocated memory during parsing, resulting in memory corruption. The issue is reachable by a remote, unauthenticated attacker and does not require user interaction according to the available vulnerability metadata.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains a README and two standalone Python 3 PoC generators: one for a TIFF payload associated with CVE-2026-21045 and one for a DNG payload associated with CVE-2026-21048. Neither script performs network communication, device interaction, exploitation orchestration, or post-exploitation actions; each constructs and writes a malformed local image file. The generated files contain standard little-endian TIFF headers and minimal IFDs, plus an attacker-controlled IFD entry with count 0xFFFF0001 and offset 0x17FFF. The files are padded to 0x8000 bytes so the claimed 32-bit unsigned addition wraps to the apparent buffer length while the referenced offset remains out of bounds. The intended delivery vector is opening or otherwise ingesting the image through Samsung Gallery or another component using the affected Quram decoder. This is a crash/heap-corruption PoC rather than a weaponized RCE exploit: no shellcode, command execution, persistence, callback, or configurable code-execution payload is present.
Repository contains two standalone Python proof-of-concept generators and a detailed README. The PoCs target Samsung Android devices that use Quramsoft's libimagecodec.quram.so for TIFF/DNG parsing and are vulnerable prior to SMR Jul-2026 Release 1. Both scripts construct malformed image files by building minimal TIFF-compatible headers and IFD structures, then inserting a malicious directory entry whose count (0xFFFF0001) and value/offset (0x00017FFF) cause a 32-bit unsigned wraparound in the target's bounds check inside WINKJ_ReadExifField. The TIFF PoC uses an ASCII ImageDescription tag (0x010E); the DNG PoC uses an UNDEFINED tag (0xCFFF) while also adding plausible DNGVersion metadata. Each script pads the file to 0x8000 bytes so the wrapped arithmetic result equals the apparent buffer size, allowing the check to pass while the actual offset points far beyond the buffer. There is no network communication, command execution, persistence, or post-exploitation logic; the repository's purpose is to generate malformed files for local delivery/opening to demonstrate crash and heap corruption conditions. The README provides vulnerability background, affected devices, binary-analysis notes, example adb-based trigger steps, and references.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Out-of-bounds write vulnerability in the TIFF file parser within Samsung Mobile's libimagecodec.media.quram.so library that could allow arbitrary code execution by a remote unauthenticated attacker.
An out-of-bounds write vulnerability in TIFF parsing within libimagecodec.media.quram.so on Samsung Mobile Devices, affecting versions prior to SMR Jul-2026 Release 1.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.