Three Galaxy flaws exploitable with no user action, fixed in the July update (CVE-2026-21047)
Samsung's July 2026 Galaxy update fixes three flaws exploitable with no user action. Two sit in the same image codec that spyware exploited last year.
Table of contents
Samsung's July 2026 Galaxy update fixes three flaws exploitable with no user action. Two sit in the same image codec that spyware exploited last year.
Samsung's July 2026 security update for Galaxy devices turns out to include three vulnerabilities that can be exploited remotely without the owner doing anything at all. No link to tap, no app to install.
One is in the telephony core; the other two are in image decoding. And the two image flaws sit in the same component family that spyware actually exploited last year. That said, none of today's three has been reported as attacked.
The fix is simple: install the July security update (SMR Jul-2026 Release 1). It has already reached most models. Below: what each flaw does, how to check whether your phone has the patch, and β importantly β which models will never receive it.
The three that need no user action
The July update carries 57 fixes in total β 41 from Google's shared Android patches and 16 of Samsung's own. Fourteen of Samsung's are described publicly (two are withheld). Of those, exactly three are marked "remote"; every other one is "local", meaning it helps an attacker who is already on the device escalate privileges.
| Identifier | Where | What it allows | Samsung rating |
|---|---|---|---|
| CVE-2026-21047 | Telephony core (ImsService) | Remote code execution | High |
| CVE-2026-21045 | Image decoding (TIFF) | Remote out-of-bounds memory write | High |
| CVE-2026-21048 | Image decoding (DNG) | Remote out-of-bounds memory write | High |
All three are out-of-bounds writes β the program writes past the end of the memory it reserved. When an attacker can steer what lands beyond that boundary, they can make the device run instructions of their choosing.
CVE-2026-21047: the first "remote" flaw in the telephony core
ImsService sounds obscure but it is something you use daily. IMS is how carriers deliver voice and messaging over IP: VoLTE calling, Wi-Fi calling, and RCS messaging all run on it. Android's design leaves this layer to the device maker or carrier, and Galaxy phones carry Samsung's implementation.
Samsung's wording is notably hedged: remote attackers can potentially execute arbitrary code. Severity is 8.3 on CVSS 4.0, but the vector marks attack requirements as present β this is not something anyone can fire from anywhere. It reads as needing a position on the signalling path, such as a rogue base station.
What stands out is that this is the first remote flaw disclosed in this component. The earlier ImsService issues (CVE-2025-21026, -21027 and -21031, all published September 2025) were local-only and rated Moderate. The same place, but the reach has moved up a class.
CVE-2026-21045 / 21048: decoding an image is enough
The other two are in the conversion routines Galaxy uses to display pictures β TIFF for 21045 and DNG for 21048. DNG is one of the RAW photo formats, supported by Galaxy cameras. Feed the phone a crafted image and memory is written outside its bounds.
Image-parsing flaws are dangerous because they can land simply by sending something the target views β attached to a message, embedded in a web page. CVE-2026-21045 came in through ZDI, the programme that buys vulnerability research and passes it to vendors; 21048 came from an independent researcher.
The image flaws share a component with last year's spyware
This is the part worth pausing on. CVE-2026-21045 and 21048 live in the Quram image codec that handles picture decoding on Galaxy devices. And in 2025, flaws in that very component were used as a spyware entry point in the real world.
Those were CVE-2025-21042 and CVE-2025-21043, both out-of-bounds writes in the same Quram codec, both added to CISA's catalogue of vulnerabilities confirmed under attack (KEV) in October and November 2025. Security researchers reported that commercial-grade Android spyware used the hole to get onto Galaxy phones.
To be clear: today's 21045 and 21048 are not those bugs and are not known to be in any attack. They are separate flaws. But the same component has now produced repeated "just decode this image" write primitives within a year, and the previous round was genuinely exploited β a weight the severity number alone does not convey.
The saving grace is that the remedy is identical. One July update closes all three.
Who goes after this, and why
Flaws like these are not for people spraying attacks at random. The realistic buyers are those who want inside one specific person's phone β commercial spyware vendors, and the customers who pay them to watch journalists, activists and senior corporate figures. The previous Quram round was used in exactly that shape.
What they are buying is a way into the device that the owner never notices. A flaw needing no user action is the most valuable kind for that purpose, which is why it commands a high price and gets used sparingly against chosen targets. Spraying it broadly would get it discovered β which, conversely, means the ordinary user is unlikely to be hit.
So for most people this is not a drop-everything situation. But the update is being handed out, so there is no reason to skip it. And if you are a journalist, lawyer, researcher, or someone whose decisions are worth surveilling, the calculus changes.
How to check whether your phone is patched
This takes about thirty seconds. Go to Settings β About phone β Software information and read the "Security software version" line. If it says SMR Jul-2026 Release 1 or later, you are covered. Samsung states that this single indicator includes both its own patches and Google's.
If not, apply it via Settings β Software update β Download and install. Rollout began around July 7; the Galaxy S25 series went global in mid-July and other models followed through late July. Samsung's standard caveats apply: delivery timing varies by region and model, and some carriers only support quarterly updates.
Update cadence differs by device. Monthly covers the S26, S25, S24 and S23 series, Z Fold and Z Flip generations 4 through 7, the A56 5G and several enterprise models. Quarterly covers the S22 series, S21 FE, Z Fold3 and Flip3, much of the A/M/F lines and the Tab range β those arrive later.
And some devices will not receive it at all. Anything absent from Samsung's published support scope β Galaxy S21 / S21+ / S21 Ultra (excluding the FE), the S20 series and older, the Note line, first- and second-generation Z Fold and Z Flip, and A-series models at A52 / A72 and older. Samsung does not publish an explicit end-of-life statement, so this is by absence from the scope page rather than an affirmative declaration β but on those handsets these three flaws stay open. For devices from January 2024 onward, Samsung has committed to up to seven years of security updates.
What this means in Japan
Japan is a useful illustration of the installed base. Per MM Research Institute's FY2025 domestic shipment survey (April 2025 β March 2026), Samsung shipped 3.531 million units for an 11.0% share, third place, behind Apple (50.1%) and Google (12.4%). Looking at devices actually in use, an MMD Labo survey of 40,000 people in February 2026 put Galaxy at 14.3% among Android users, fourth behind AQUOS, Xperia and Pixel.
Distribution is broad: the Galaxy S26 series, launched March 2026, is sold by all four carriers β NTT docomo, au, SoftBank and Rakuten Mobile β alongside SIM-free channels and Samsung's own stores in Harajuku and Osaka.
One local note on the telephony flaw: VoLTE is standard across all four Japanese carriers, so IMS is always in use. There is no "I don't use that feature" exemption. That said, as noted above, the attack is assessed as requiring a position on the signalling path β this is not something you stumble into during normal use.
Nobody is talking about it β which is not the same as safe
Finally, an honest accounting of what is and is not known.
Known. None of the three is in CISA's KEV catalogue. No EPSS exploitation-likelihood score exists yet for CVE-2026-21047 (the two image flaws sit around 0.004, which is low). No exploit code has surfaced. CISA's own assessment records exploitation as "none" and automatability as "no". Samsung itself rates all three High, not Critical β and there are no Critical items among Samsung's own findings in this month's bulletin at all.
Unknown. No technical detail has been published. Which path an attacker uses, and what they must send, is not public. Also worth noting: CVE-2026-21047's identifier was published 18 days after the July bulletin itself, out of step with its siblings, and no reason was given.
And there is almost no coverage. At the time of writing we found no major security outlet anywhere naming CVE-2026-21047. In Japanese, a single corporate blog post on July 15 summarised the 57 fixes but did not mention this flaw. It has no entry in Japan's JVN vulnerability database, nor any JPCERT/CC or IPA advisory. None of that is evidence of safety β it reflects how new this is. With the previous Quram codec flaws, exploitation only became public months after the patch shipped. Doing this while it is quiet is the cheap option.
Summary
Samsung's July 2026 Galaxy security update contains three flaws exploitable remotely with no user action: CVE-2026-21047 in the ImsService telephony core (CVSS 4.0 8.3), and CVE-2026-21045 and 21048 in image decoding. No exploitation has been reported, and Samsung rates all three High rather than Critical.
The action is simply to apply SMR Jul-2026 Release 1, and you can confirm it in thirty seconds under Settings β About phone β Software information. Two things to carry away: the image flaws come from the same component that spyware exploited last year, and some models, including the S21 series and older, will never get this update β on those, the three flaws remain open. We will update this article if new information or confirmed exploitation appears.
Sources
- βΈ Samsung Mobile Security - July 2026 security update (SMR Jul-2026)
- βΈ NVD - CVE-2026-21047 (ImsService)
- βΈ NVD - CVE-2026-21045 (TIFF decoding)
- βΈ NVD - CVE-2026-21048 (DNG decoding)
- βΈ Samsung Mobile Security - security update support scope by model
- βΈ Android Open Source Project - IMS (ImsService) documentation
- βΈ Unit 42 - analysis of the 2025 spyware that exploited the Quram codec flaws
- βΈ MM Research Institute - FY2025 Japanese handset shipment survey (Japanese)
- βΈ Samsung - how to update software

Makoto Horikawa
Backend Engineer / AWS / Django