Junglewise Threat Intelligence

CVE-2026-21093: Samsung PROCA trustlet stack buffer overflow

CVE-2026-21093 · Severity: medium · CVSS 6.7 · Published 2026-09-09

Vendors: Samsung.

Executive brief

Samsung's PROCA trustlet, a security component in mobile devices, contains a stack-based buffer overflow vulnerability that allows a privileged attacker with local access to write data outside intended memory boundaries. While exploitation requires existing elevated privileges, successful exploitation could lead to further privilege escalation, denial of service, or compromise of security-critical functions within the trusted execution environment.

Technical details

A stack-based buffer overflow vulnerability exists in Samsung's PROCA trustlet, a security-critical component operating in the trusted execution environment (TEE). The vulnerability allows a local privileged attacker to write data out-of-bounds on the stack, potentially corrupting adjacent memory structures and sensitive data. The attack requires existing elevated (privileged) system access and is network-isolated to local execution only. Successful exploitation could enable further privilege escalation within the TEE or compromise security-critical cryptographic or attestation functions. Samsung patched this vulnerability in the September 2026 Security Maintenance Release (SMR).

Affected products

  • Samsung PROCA trustlet prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed
  • 2026-09: patched: SMR Sep-2026 Release 1

References