Heap-based Buffer Overflow in KnoxVault Trustlet Affects Samsung Devices
CVE-2026-21104

7.1HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21104?

A heap-based buffer overflow has been identified in the KnoxVault trustlet, affecting versions prior to the SMR September 2026 Release 1. This vulnerability enables local privileged attackers to execute arbitrary code, potentially compromising device security and integrity. Users of affected devices need to ensure timely updates to mitigate this risk.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in hwvault ta

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.