CVE-2026-49509
Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers. This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630.
CVSS v3.1
Current4.4MEDIUMPSIRT@samsung.comAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Attack Vector
LocalAV:L
Attack Complexity
LowAC:L
Privileges Required
NonePR:N
User Interaction
RequiredUI:R
Scope
UnchangedS:U
Confidentiality Impact
LowC:L
Integrity Impact
NoneI:N
Availability Impact
LowA:L
CVSS temporel
Estimation3.9E:U/RL:U/RC:R
Temporal score updated on 4 Sept 2026, 07:36
Source: PatchCVE heuristic estimate (CISA KEV, EPSS from FIRST.org, NVD reference tags, NVD status) — not published by a CNA.
Exploit Code Maturity
UnprovenE:U
No known exploit
No known exploit: absent from CISA KEV and exploit-db, no reference tagged Exploit, SSVC reports no exploitation — Unproven
Remediation Level
UnavailableRL:U
No reference tagged as fix or vendor advisory found
Report Confidence
ReasonableRC:R
NVD status: Received
References — 3
- https://nvd.nist.gov/vuln/detail/CVE-2026-49509(nvd.nist.gov)Official source
- https://github.com/Samsung/rlottie/pull/604(PSIRT@samsung.com)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70848(euvd.enisa.europa.eu)Official source