ThreatCluster

Samsung KNOX UAF Vulnerability Exposes Millions of Devices to Risk

2h ago CybersecuritynewsSecurityaffairs.Co 85% similarity 71
Share:

Article Content

Browse articles
ThreatCluster

A critical use-after-free (UAF) vulnerability in Samsung's KNOX security subsystem, identified as CVE-2026-20971, has been discovered after remaining hidden for over eight years. This flaw affects hundreds of millions of Galaxy devices, allowing potential kernel-level memory corruption and complete device takeover. The vulnerability was patched in Samsung's January 2026 Android Security Update. Security research firm LucidBit revealed the flaw, which resides in the PROCA/FIVE components of the KNOX stack. Experts emphasize the severity of this issue, as it exists in software designed to enhance device security. Users of affected devices are urged to apply the security update to mitigate risks associated with this vulnerability.

Key Points: • CVE-2026-20971 is a critical UAF vulnerability affecting Samsung KNOX. • The flaw could allow complete device takeover on hundreds of millions of Galaxy devices. • Samsung released a patch for this vulnerability in January 2026.

ThreatCluster AI

Timeline

2026-01-09
CVE-2026-20971 published
The vulnerability was officially published, detailing its potential for kernel-level exploitation.
Securityaffairs.Co
2026-01-2026
Samsung patches the vulnerability
Samsung issued a patch in its January 2026 Android Security Update to address the UAF flaw.
Cybersecuritynews
Recent
Vulnerability disclosed by LucidBit
Security research firm LucidBit announced the discovery of the hidden UAF vulnerability in Samsung's KNOX.
Cybersecuritynews

Community

Browse all →