Junglewise Threat Intelligence

CVE-2026-21046: Samsung Mobile fabricKeymaster race condition in trustlet

CVE-2026-21046 · Severity: info · CVSS 8.4 · Published 2026-07-10

Vendors: Samsung.

Executive brief

A security vulnerability exists in the fabricKeymaster component of Samsung mobile devices, which is responsible for managing cryptographic keys. A local attacker with high privileges could exploit a timing-related flaw to bypass security checks and execute unauthorized code. This could lead to a complete compromise of the device's secure environment and the sensitive data stored within it.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition exists in the fabricKeymaster trustlet on Samsung mobile devices running Android 14, 15, and 16. The vulnerability occurs when the system checks a condition (such as a memory buffer or state) but that condition changes before the system actually uses the result of that check. A local attacker with administrative or high privileges can exploit this race condition to achieve arbitrary code execution within the Trusted Execution Environment (TEE). This flaw is addressed in the Samsung Security Maintenance Release (SMR) for July 2026.

Affected products

  • Samsung Mobile Devices (Android 14, 15, 16) Prior to SMR Jul-2026 Release 1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory
  • 2026-07-01: patched: Addressed in SMR Jul-2026 Release 1

References