CVE-2018-10751

MEDIUM

Samsung Mobile - Memory Corruption via OMACP WbXml String Extension Processing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-10751. PoCs published by Google Security Research.

AI-analyzed exploit summary The exploit leverages an integer overflow in Samsung's OMACP WAP push SMS handling, causing memory corruption and a crash (DoS) on Samsung S7 Edge devices. The malformed WbXML payload triggers the vulnerability pre-authentication during credential extraction.

Description

A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosandroid
https://www.exploit-db.com/exploits/44724

The exploit leverages an integer overflow in Samsung's OMACP WAP push SMS handling, causing memory corruption and a crash (DoS) on Samsung S7 Edge devices. The malformed WbXML payload triggers the vulnerability pre-authentication during credential extraction.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Samsung S7 Edge (build NRD90M.G93FXXU1DQJ8)
No auth needed
Prerequisites: Access to a separate Android device with SMS permissions · Target phone number
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44724/
Third Party Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 5.3
EPSS 0.0875
EPSS Percentile 94.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-190
Status published
Products (5)
samsung/samsung_mobile 6.0
samsung/samsung_mobile 7.0
samsung/samsung_mobile 7.1
samsung/samsung_mobile 7.1.1
samsung/samsung_mobile 7.1.2
Published May 29, 2018
Tracked Since Feb 18, 2026