Junglewise Threat Intelligence

CVE-2026-21104: Samsung KnoxVault heap-based buffer overflow

CVE-2026-21104 · Severity: medium · CVSS 6.7 · Published 2026-09-09

Vendors: Samsung.

Executive brief

KnoxVault is Samsung's secure vault for storing sensitive data on mobile devices. A heap-based buffer overflow vulnerability in the KnoxVault trustlet (a highly privileged system component) allows an attacker with local privileged access to execute arbitrary code with elevated permissions, potentially compromising all data stored in the vault and system security.

Technical details

A heap-based buffer overflow exists in the KnoxVault trustlet, a privileged secure execution environment component on Samsung mobile devices. The vulnerability allows a local attacker with privileged system access to write beyond the bounds of an allocated heap buffer, corrupting memory and executing arbitrary code within the trustlet context. This requires local code execution at the privileged level as a precondition. Successful exploitation could result in complete compromise of the trustlet and all vault operations. Samsung addressed this issue in the SMR September 2026 Release 1 security update.

Affected products

  • Samsung KnoxVault prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed

References