ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability
Executive Summary
A stack-based buffer overflow in Samsung's rlottie library allows remote attackers to execute arbitrary code. Exploitation requires interaction with rlottie and may vary by implementation. The Zero Day Initiative assigned CVSS 7.8 and CVE-2026-91826.
Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-17T05:00:00+00:00 - Category: cves
Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.
"Every day may not be good, but there's something good in every day."
— Unknown