ZeroHour

CVE-2026-21085

mass

Out-of-Bounds Write in Samsung Keymaster Trustlet (SMR Sep-2026)

CVSS 4.0
8.4 high
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-21085 is an out-of-bounds write vulnerability in the Keymaster trustlet, the secure-world (TEE) component on Samsung mobile devices that manages cryptographic key material and device security operations. The flaw is triggered when a local privileged attacker (an attacker who has already gained high privileges on the device) causes the trustlet to write beyond its allocated memory buffer. A successful exploit yields high-impact compromise of the vulnerable secure component, with high ratings for confidentiality, integrity, and availability, though the attack does not propagate to the normal system per the CVSS scoring. Affected devices are Samsung mobile devices that have not received Samsung's SMR Sep-2026 Release 1 security maintenance release. As of now, there is no evidence of exploitation in the wild, no known public proof-of-concept, and the flaw is not in the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply Samsung's SMR Sep-2026 Release 1 (security patch level September 2026 or later) via the device software-update mechanism and confirm the installed patch level in Settings. Because exploitation requires local privileged access, risk of standalone remote compromise is low, but patching closes the flaw for use in chained attacks where an attacker has already gained elevated privileges on the device.

Affected
Samsung mobile devices (Keymaster trustlet / TEE component)Prior to SMR Sep-2026 Release 1
Estimated exposure
masshundreds of millions of Samsung Galaxy devices in the installed base; exact count of currently unpatched devices unknown — The Keymaster trustlet ships on Samsung's Android device lineup, which sells hundreds of millions of units annually, so the exposed fleet is at minimum the portion of that massive installed base not yet running SMR Sep-2026 Release 1.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Vendors
samsung
Products
android
Weakness
CWE-787
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.