Samsung patches critical KNOX flaw exposing Galaxy devices to takeover risks

Samsung patches critical KNOX flaw exposing Galaxy devices to takeover risks

William Johnston
William Johnston
1 Min.
Samsung KNOX Kernel UAF Exposes Millions of Galaxy Devices

Samsung patches critical KNOX flaw exposing Galaxy devices to takeover risks

Samsung has fixed a critical security flaw in its KNOX security platform. The vulnerability, identified as CVE-2026-20971, was addressed in the January 2026 software update. It affected a wide range of Galaxy devices, including models from the S9 to S25 series, as well as various A-series phones. The issue was a kernel use-after-free (UAF) vulnerability found in the interaction between two KNOX subsystems, PROCA and FIVE. A race condition during process state changes, such as forking or calling execve(), could trigger the bug. This allowed local, untrusted apps to corrupt kernel memory with user interaction.

If exploited, the flaw could lead to a complete device takeover. Security controls in the kernel were not immune, as they could also be part of the attack surface. The vulnerability impacted both Exynos- and Qualcomm-based models running Android 13 to 16. Samsung resolved the issue with its January 2026 patch. The fix highlights the need for prompt updates, especially on mobile devices that remain active and connected at all times. Users are advised to install the latest security update to protect their devices.

Neueste Nachrichten