Impact
A race condition known as time‑of‑check to time‑of‑use exists in the FabricKeymaster trustlet shipped with Samsung Mobile firmware versions released before the SMR Jul‑2026 Release 1 update. The flaw permits an attacker who already possesses privileged local access to orchestrate the timing of trustlet operations and inject or execute arbitrary code, effectively granting the attacker the same privilege level as the trustlet.
Affected Systems
Samsung Mobile Devices running firmware versions released prior to the SMR Jul‑2026 Release 1 update are affected. The vulnerability is confined to the FabricKeymaster trustlet bundled in those firmware builds; no separate sub‑product or additional version details are provided.
Risk and Exploitability
The CVSS score of 8.4 classifies the vulnerability as high severity. The EPSS score, less than 1%, suggests the likelihood of exploitation is low in the short term. Because the flaw is purely local and requires privileged execution, its impact is limited to devices that have not applied the latest firmware update and are not listed in the CISA KEV catalog.
OpenCVE Enrichment