CVE-2026-21104
massHeap Buffer Overflow in Samsung KnoxVault Trustlet Allows Local Code Execution
CVE-2026-21104 is a heap-based buffer overflow in the KnoxVault trustlet, the trusted-execution-environment component on Samsung Galaxy devices that stores and manages protected cryptographic key material. The flaw is triggered by a local attacker who has already obtained privileged (root/system-level) code execution on the device, though the high attack complexity in the CVSS 4.0 vector suggests reliably exploiting it is non-trivial. A successful attacker gains arbitrary code execution in the trustlet context, with the CVSS vector indicating high confidentiality and integrity impact to the vulnerable component — plausibly including access to or manipulation of keys that KnoxVault safeguards. All Samsung Galaxy devices that include the KnoxVault trustlet and are running software prior to the September 2026 Security Maintenance Release (SMR Sep-2026 Release 1) are affected. There is no evidence of exploitation so far: the issue is not in CISA's KEV, no public proof-of-concept is known, and the CVSS exploit status is unconfirmed.
What to do: Apply Samsung's SMR Sep-2026 Release 1 as soon as it reaches affected devices via Settings > Software update, and verify the device's security patch level shows the September 2026 update. Because exploitation requires an attacker to already hold privileged code execution on the device, prioritize patching devices that store high-value credentials or keys in KnoxVault, and avoid sideloading or granting privileged access to untrusted apps on unpatched devices. There are no known workarounds; the September 2026 security release is the fix.
| Samsung KnoxVault trustlet (as shipped in Samsung Galaxy mobile devices) | All versions prior to SMR Sep-2026 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-122
- Vector
- CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.