CVE-2026-21046 Details
Description
Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.
A time-of-check time-of-use race condition has been identified in the fabricKeymaster trustlet, affecting Samsung devices running Android versions 14, 15, and 16, prior to the July 2026 Security Maintenance Release. This vulnerability allows local privileged attackers to execute arbitrary code by exploiting the timing of checks and usage in the trustlet.
Users can apply the July 2026 Security Maintenance Release to address this vulnerability. This update is part of the monthly security update process and includes patches from both Google and Samsung.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Samsung Android | >= 14, < 15 >= 15, < 16 >= 16, < 17 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 11, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion