Samsung FabricKeymaster Trustlet Time-of-Check Time-of-Use Race Condition Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A time-of-check time-of-use race condition has been identified in the fabricKeymaster trustlet, affecting Samsung devices running Android versions 14, 15, and 16, prior to the July 2026 Security Maintenance Release. This vulnerability allows local privileged attackers to execute arbitrary code by exploiting the timing of checks and usage in the trustlet.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code within the context of the trustlet.

Remediation

Users can apply the July 2026 Security Maintenance Release to address this vulnerability. This update is part of the monthly security update process and includes patches from both Google and Samsung.

Added: Jul 10, 2026, 5:24 AM
Updated: Jul 10, 2026, 5:24 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
7.5
exploitability
2.4
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.