ZeroHour

CVE-2026-21104

mass

Heap Buffer Overflow in Samsung KnoxVault Trustlet Allows Local Code Execution

CVSS 4.0
7.1 high
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-21104 is a heap-based buffer overflow in the KnoxVault trustlet, the trusted-execution-environment component on Samsung Galaxy devices that stores and manages protected cryptographic key material. The flaw is triggered by a local attacker who has already obtained privileged (root/system-level) code execution on the device, though the high attack complexity in the CVSS 4.0 vector suggests reliably exploiting it is non-trivial. A successful attacker gains arbitrary code execution in the trustlet context, with the CVSS vector indicating high confidentiality and integrity impact to the vulnerable component — plausibly including access to or manipulation of keys that KnoxVault safeguards. All Samsung Galaxy devices that include the KnoxVault trustlet and are running software prior to the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1) are affected. There is no evidence of exploitation so far: the issue is not in CISA's KEV, no public proof-of-concept is known, and the CVSS exploit status is unconfirmed.

What to do: Apply Samsung's SMR Sep-2026 Release 1 as soon as it reaches affected devices via Settings > Software update, and verify the device's security patch level shows the September 2026 update. Because exploitation requires an attacker to already hold privileged code execution on the device, prioritize patching devices that store high-value credentials or keys in KnoxVault, and avoid sideloading or granting privileged access to untrusted apps on unpatched devices. There are no known workarounds; the September 2026 security release is the fix.

Affected
Samsung KnoxVault trustlet (as shipped in Samsung Galaxy mobile devices)All versions prior to SMR Sep-2026 Release 1
Estimated exposure
masshundreds of millions of Galaxy devices (KnoxVault ships on effectively the entire modern Galaxy smartphone/tablet installed base) — The KnoxVault trustlet is bundled with the Knox platform on essentially all recent Samsung Galaxy phones and tablets, and Samsung's global installed base of Galaxy devices is on the order of hundreds of millions to roughly a billion,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Vendors
samsung
Products
android
Weakness
CWE-122
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.