Impact
An out‑of‑bounds write flaw exists in the Keymaster trustlet of Samsung Mobile devices. The vulnerability allows a local user with privileged rights to corrupt memory beyond intended bounds, potentially leading to arbitrary code execution or compromise of system integrity. The weakness is a classic out‑of‑bounds write issue that can subvert application flow or corrupt critical data structures.
Affected Systems
Samsung Mobile Devices running a version of the Keymaster trustlet prior to the SMR Sep‑2026 Release 1 are affected. The specific model or firmware revision is not listed, but any device that has not applied the September 2026 update contains the vulnerable trust.
Risk and Exploitability
The CVSS score of 8.4 classifies this as a high‑severity vulnerability. No EPSS score is available, and the issue is not recorded in the CISA KEV catalog, suggesting no widespread exploitation has been observed yet. Attackers must already possess local privileged access to exploit the flaw, but the capability to overwrite memory can lead to full privilege escalation on the device. Given the high severity and the local nature of the attack vector, the risk to users with elevated privileges is significant.
OpenCVE Enrichment