Samsung patches critical KNOX flaw exposing Galaxy devices to full takeover
Samsung patches critical KNOX flaw exposing Galaxy devices to full takeover
Samsung patches critical KNOX flaw exposing Galaxy devices to full takeover
Samsung has addressed a critical kernel vulnerability in its KNOX security stack. The flaw, tracked as CVE-2026-20971, affects a wide range of Galaxy devices. It allows untrusted apps to trigger kernel memory corruption and potentially take full control of the device. The issue stems from a use-after-free (UAF) vulnerability in KNOX, caused by improper input validation in SecSettings. It arises from a race condition during process state changes, such as forking or calling execve(). Attackers can exploit this to read a pointer to freed memory, creating a live UAF with a real corruption path.
The vulnerability involves the interaction between two kernel-side subsystems of KNOX: PROCA and FIVE. Affected devices include Galaxy S9 through Galaxy S25, A-series models, and both Exynos- and Qualcomm-based handsets running Android 13 to 16.
Samsung’s Kernel Call Filtering Infrastructure (KCFI) provides partial mitigation but does not fully block exploitation. The company released a patch for the issue in the January 2026 security update. The fix is now available through Samsung’s monthly security release. Users of affected devices are advised to install the update to prevent potential device takeover. The vulnerability underscores that even kernel-level security controls can become part of the attack surface.