PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47312 Samsung Open Source CVE debrief

A use-after-free vulnerability in Samsung's Escargot JavaScript engine allows local attackers to cause denial of service through buffer manipulation. The issue affects a specific commit (590345cc6258317c5da850d846ce6baaf2afc2d3) of the open-source project. A fix has been proposed via pull request.

Vendor
Samsung Open Source
Product
Escargot
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-19
Original CVE updated
2026-07-24
Advisory published
2026-05-19
Advisory updated
2026-07-24

Who should care

Organizations deploying Samsung Escargot JavaScript engine in embedded systems, IoT devices, or applications processing untrusted JavaScript code. Security teams tracking open-source engine vulnerabilities and developers maintaining Escargot-based products.

Technical summary

CVE-2026-47312 is a use-after-free vulnerability (CWE-763) in Samsung's open-source Escargot JavaScript engine. The flaw exists in commit 590345cc6258317c5da850d846ce6baaf2afc2d3 and allows buffer manipulation through improper release of an invalid pointer or reference. The vulnerability requires local access and user interaction, with no confidentiality or integrity impact but high availability impact (denial of service). Samsung PSIRT has identified the weakness and referenced a fix in GitHub PR #1565. NVD currently lists the entry as 'Undergoing Analysis', indicating technical details may be refined.

Defensive priority

medium

Recommended defensive actions

  • Review Samsung Escargot deployments and identify systems running commit 590345cc6258317c5da850d846ce6baaf2afc2d3 or earlier
  • Monitor GitHub PR #1565 for merge status and official release tagging
  • Apply updated Escargot version once Samsung releases patched build
  • Restrict execution of untrusted JavaScript in Escargot-based applications as interim mitigation
  • Track NVD 'Undergoing Analysis' status for CVSS revisions or additional technical details

Evidence notes

NVD lists this as 'Undergoing Analysis' with CVSS 3.1 score 5.5 (MEDIUM). CWE-763 (Release of Invalid Pointer or Reference) assigned by Samsung PSIRT. Fix reference points to GitHub PR #1565.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47312 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47312

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47312 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47312

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.