CVE-2024-56426Active Exploitation(samsung / exynos_1080)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for samsung exynos_1080 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000. The lack of a length check leads to out-of-bounds writes via malformed USB packets to the target.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exynos_1080
  • exynos_1080_firmware
  • exynos_1280
  • exynos_1280_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
exynos_1080exynos_1080_firmwareexynos_1280exynos_1280_firmwareexynos_1330exynos_1330_firmwareexynos_1380exynos_1380_firmwareexynos_1480exynos_1480_firmware

1 version affected across 28 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Active Exploitation · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • dani@Dan50798734
    Active Exploitation

    @zippgod24 If it mentions "early 2020" then it's using CVE-2021-30327. We're still yet to see a retail kona chipset with this bug. SM8150-AA is affected, hard to exploit. About samsung, they're likely using the houston (CVE-2024-56426) exploit.

    Post summary

    The tweet cites CVE-2021-30327 and CVE-2024-56426, notes an affected SM8150‑AA device, and implies Samsung may be exploiting CVE-2024-56426, but provides no PoC or patch information.

    1000066
    13 followersView on X
CPE platform detail28 entries

28 of 28 entries

PartVendorProductVersionTarget SWTarget HW
HWsamsungexynos_1080---
OSsamsungexynos_1080_firmware---
HWsamsungexynos_1280---
OSsamsungexynos_1280_firmware---
HWsamsungexynos_1330---
OSsamsungexynos_1330_firmware---
HWsamsungexynos_1380---
OSsamsungexynos_1380_firmware---
HWsamsungexynos_1480---
OSsamsungexynos_1480_firmware---
HWsamsungexynos_2100---
OSsamsungexynos_2100_firmware---
HWsamsungexynos_2200---
OSsamsungexynos_2200_firmware---
HWsamsungexynos_2400---
OSsamsungexynos_2400_firmware---
HWsamsungexynos_850---
OSsamsungexynos_850_firmware---
HWsamsungexynos_980---
OSsamsungexynos_980_firmware---
HWsamsungexynos_990---
OSsamsungexynos_990_firmware---
HWsamsungexynos_w1000---
OSsamsungexynos_w1000_firmware---
HWsamsungexynos_w920---
OSsamsungexynos_w920_firmware---
HWsamsungexynos_w930---
OSsamsungexynos_w930_firmware---

Explore more