Samsung Galaxy Flaw Lets Malicious Images Execute Code Without a Tap

Samsung Galaxy September 2026 Security Update Fixes Critical Image Decoder Flaws

Samsung has started rolling out its September 2026 security update for Galaxy devices, and this one is more important than a routine monthly patch. Released on September 8 as SMR Sep-2026 Release 1, the update includes 90 security fixes, including two critical vulnerabilities tied to how Galaxy phones process image files.

The two critical flaws are listed as SVE-2026-3247 and SVE-2026-3282, and they are publicly tracked as CVE-2026-21095 and CVE-2026-21096. Both issues affect libimagecodec.quram.so, a Samsung image-processing library used on Galaxy devices.

One vulnerability impacts the DNG image decoder, while the other affects the JPEG decoder. DNG is a raw photo format commonly used by cameras and smartphones, while JPEG remains one of the most widely used image formats in the world. Because these formats are so common, security issues in image decoders can be especially serious.

Samsung describes both flaws as heap-based buffer overflow vulnerabilities. In simple terms, this type of bug can allow specially crafted image files to interfere with memory handling on a device. In the worst-case scenario, a remote attacker could use such a flaw to run arbitrary code on the affected phone.

The vulnerabilities affect Galaxy devices running Android 14, Android 15, Android 16, and Android 17.

What makes these Galaxy security flaws serious

The severity rating explains why Galaxy users should not ignore this update. Samsung’s filing gives the vulnerability a CVSS score of 9.2 out of 10, placing it in the critical range.

The most concerning detail is that the attack path is listed as requiring no user interaction. That means a victim would not necessarily need to open a file, tap an attachment, or approve anything for the device to be exposed. The phone would only need to process a maliciously crafted image under the right conditions.

There is one important limitation: the vulnerability also requires specific attack conditions to be met. In other words, it is not automatically exploitable in every situation. Even so, the combination of image parsing, no required user action, and potential remote code execution makes this a high-priority fix.

The two vulnerabilities were discovered by Brendon Tiszka and Mateusz Jurczyk of Google Project Zero. Samsung notes that the issues were privately disclosed, which means there are currently no public reports suggesting these exact flaws have been exploited in real-world attacks.

Samsung says the fix adds proper input validation, a security measure designed to ensure malformed image data is handled safely before it can trigger memory corruption.

Why Galaxy image decoder security matters

Image-processing flaws are especially dangerous because modern smartphones constantly handle images in the background. Photos may appear in messaging apps, galleries, browsers, cloud services, email clients, and social platforms. Users often do not think of an image as a potential security risk, but image decoders are complex pieces of software that can become attractive targets for attackers.

Samsung’s libimagecodec.quram.so library has also been a concern in the past. In 2025, attackers exploited a separate flaw in the same image-processing component to deliver commercial spyware known as Landfall. That earlier attack involved malformed DNG files sent through WhatsApp and reportedly compromised phones without requiring the victim to click anything.

Samsung patched that older vulnerability, tracked as CVE-2025-21042, in April 2025. It was later added to the U.S. cybersecurity agency’s catalog of known exploited vulnerabilities. Reported targets included users in Iraq, Iran, Turkey, and Morocco.

The newly patched September 2026 flaws are separate from that earlier vulnerability. However, the fact that they affect the same library, and again involve image decoding, shows why this area remains an important attack surface for Galaxy device security.

What is included in the September 2026 Samsung update

Samsung’s September 2026 security package includes a total of 90 fixes. Of those, 58 come from Google’s Android security bulletin, including 18 critical fixes and 40 high-severity fixes.

Another fix comes from Samsung Semiconductor, while 31 fixes are specific to Samsung Mobile software. This combination is typical of monthly Galaxy security updates, which often include patches from Google, chipset-related fixes, and Samsung’s own device-specific improvements.

Because the two critical image decoder vulnerabilities affect Galaxy devices across several Android versions, installing the September patch is strongly recommended for anyone using an eligible Samsung phone or tablet.

How to check if your Galaxy phone is protected

You can check your Galaxy device’s security patch level in a few steps:

Open Settings.

Go to Software update.

Tap Software information.

Look for Android security patch level.

If your device shows a September 2026 security patch level, the latest protection is already installed. If it shows August 2026 or an earlier date, go back to Software update and tap Download and install.

Samsung usually rolls out monthly security updates in stages. Newer flagship Galaxy models often receive patches first, followed by older phones, tablets, and mid-range devices over the following days or weeks. If the September update is not available on your device yet, it may still be on the way depending on your model, region, and carrier.

Galaxy users should install the September 2026 patch as soon as it becomes available. While there are no confirmed attacks using these newly fixed flaws, the nature of the vulnerabilities makes them serious enough to treat as urgent. Keeping your phone updated remains one of the simplest and most effective ways to protect your data, messages, photos, and personal information.