Description
Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Published: 2026-07-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition known as time‑of‑check to time‑of‑use exists in the FabricKeymaster trustlet shipped with Samsung Mobile firmware versions released before the SMR Jul‑2026 Release 1 update. The flaw permits an attacker who already possesses privileged local access to orchestrate the timing of trustlet operations and inject or execute arbitrary code, effectively granting the attacker the same privilege level as the trustlet.

Affected Systems

Samsung Mobile Devices running firmware versions released prior to the SMR Jul‑2026 Release 1 update are affected. The vulnerability is confined to the FabricKeymaster trustlet bundled in those firmware builds; no separate sub‑product or additional version details are provided.

Risk and Exploitability

The CVSS score of 8.4 classifies the vulnerability as high severity. The EPSS score, less than 1%, suggests the likelihood of exploitation is low in the short term. Because the flaw is purely local and requires privileged execution, its impact is limited to devices that have not applied the latest firmware update and are not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 07:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the SMR Jul‑2026 Release 1 firmware update to patch the FabricKeymaster trustlet.
  • If a firmware upgrade cannot be performed immediately, disable or restrict the FabricKeymaster trustlet for local processes that may gain privileged status to mitigate the race condition.
  • Perform an asset inventory to identify all Samsung Mobile Devices still running the affected firmware and prioritize their upgrade.
  • Enforce least privilege for local processes on the device, limiting untrusted applications from acquiring privileged status to reduce the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 07:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title FabricKeymaster Trustlet Race Condition Enabling Local Privilege Escalation
Weaknesses CWE-617

Sat, 01 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title FabricKeymaster Trustlet Race Condition Enabling Local Privilege Escalation
Weaknesses CWE-824

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title FabricKeymaster Trustlet Race Condition Enabling Local Privilege Escalation
Weaknesses CWE-824

Thu, 23 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title FabricKeymaster Trustlet Time‑of‑Check Time‑of‑Use Race Enables Local Privilege Escalation on Samsung Mobile Devices
Weaknesses CWE-362

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title FabricKeymaster Trustlet Time‑of‑Check Time‑of‑Use Race Enables Local Privilege Escalation on Samsung Mobile Devices
Weaknesses CWE-362

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title FabricKeymaster Trustlet Local Privilege Escalation via Time‑of‑Check Time‑of‑Use Race Condition
Weaknesses CWE-617
CWE-732

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title FabricKeymaster Trustlet Local Privilege Escalation via Time‑of‑Check Time‑of‑Use Race Condition
Weaknesses CWE-617
CWE-732

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Time-of-Check Time-of-Use Race in FabricKeymaster Trustlet
Weaknesses CWE-250
CWE-409

Mon, 13 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Time-of-Check Time-of-Use Race in FabricKeymaster Trustlet
Weaknesses CWE-250
CWE-409

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Time‑of‑Check Time‑of‑Use Race in Samsung FabricKeymaster Trustlet Enables Code Execution
Weaknesses CWE-250
CWE-409

Fri, 10 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Time‑of‑Check Time‑of‑Use Race in Samsung FabricKeymaster Trustlet Enables Code Execution
Weaknesses CWE-250
CWE-409

Fri, 10 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-11T03:55:19.537Z

Reserved: 2025-12-11T01:33:35.816Z

Link: CVE-2026-21046

cve-icon Vulnrichment

Updated: 2026-07-10T12:22:34.481Z

cve-icon NVD

Status : Deferred

Published: 2026-07-10T05:16:35.290

Modified: 2026-07-11T05:16:33.380

Link: CVE-2026-21046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T07:45:05Z

Weaknesses