Impact
A time‑of‑check fabricKeymaster trustlet, enabling a local attacker who already has privileged access on the device to manipulate the execution sequence and inject arbitrary code. This flaw elevates the attacker’s privileges to that of the trustlet, compromising the confidentiality, integrity, and availability of the device.
Affected Systems
Samsung Mobile Devices that are operating on firmware released prior to the SMR Jul‑2026 Release 1 update are affected. The vulnerability resides exclusively in the FabricKeymaster trustlet bundled with those firmware versions; no separate sub‑product or additional version information is provided.
Risk and Exploitability
The CVSS score of 8.4 denotes high severity, while the EPSS of less than 1% indicates that exploitation is unlikely but not impossible. The vulnerability is not listed in CISA KEV and is purely local, requiring privileged execution; the risk remains significant only for devices that have not applied the latest firmware update.
OpenCVE Enrichment