Executive brief
A vulnerability exists in the Android StrongBox component, which is a hardware-backed security module used to protect sensitive cryptographic keys. An attacker with local access to a device could bypass certain restrictions to access keys that should otherwise be protected. This could lead to the unauthorized disclosure of sensitive information, potentially compromising the security of encrypted data or digital identities.
Technical details
An improper input validation vulnerability exists in the 'importWrappedKey' method within the KMKeymasterApplet.java component of Android's StrongBox implementation. The flaw allows a local attacker to bypass intended access restrictions on cryptographic keys. Exploitation does not require elevated privileges or user interaction, but does require local access to the device. Successful exploitation results in the disclosure of sensitive key material that should be restricted by the hardware-backed security module. The issue affects multiple hardware implementations including those from NXP, STMicroelectronics, and Thales, and is addressed in the April 2026 Android Security Bulletin.
Affected products
- Google Android StrongBox Security patch level before 2026-04-05
Timeline
- 2026-04-06: advisory: Initial publication of Android April 2026 Security Bulletin
- 2026-04-05: patched: Security patch level 2026-04-05 or later addresses this issue