Memory corruption in Quram library when decoding qmg can lead to RCE
Vulnerability Description
There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer overflow in the Quram image codec leading to an arbitrary remote code execution (RCE) without any user interaction. The Samsung ID is SVE-2020-16747.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8899
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Mateusz Jurczyk of Google Project Zero
References
More from Samsung
View All →Affected Vendor
Samsung
View all reports →