CVE-2026-21085
massOut-of-Bounds Write in Samsung Keymaster Trustlet (SMR Sep-2026)
CVE-2026-21085 is an out-of-bounds write vulnerability in the Keymaster trustlet, the secure-world (TEE) component on Samsung mobile devices that manages cryptographic key material and device security operations. The flaw is triggered when a local privileged attacker (an attacker who has already gained high privileges on the device) causes the trustlet to write beyond its allocated memory buffer. A successful exploit yields high-impact compromise of the vulnerable secure component, with high ratings for confidentiality, integrity, and availability, though the attack does not propagate to the normal system per the CVSS scoring. Affected devices are Samsung mobile devices that have not received Samsung's SMR Sep-2026 Release 1 security maintenance release. As of now, there is no evidence of exploitation in the wild, no known public proof-of-concept, and the flaw is not in the CISA Known Exploited Vulnerabilities catalog.
What to do: Apply Samsung's SMR Sep-2026 Release 1 (security patch level September 2026 or later) via the device software-update mechanism and confirm the installed patch level in Settings. Because exploitation requires local privileged access, risk of standalone remote compromise is low, but patching closes the flaw for use in chained attacks where an attacker has already gained elevated privileges on the device.
| Samsung mobile devices (Keymaster trustlet / TEE component) | Prior to SMR Sep-2026 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-787
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.