logo

8-Year-Old Samsung KNOX Vulnerability Exposes Galaxy Devices to Kernel Attacks

ID: 660663a8-a25c-574a-b4f4-3cbf3f8f74fd

STIX ID: report--660663a8-a25c-574a-b4f4-3cbf3f8f74fd

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Guru Baran

...
...

LucidBit discovered a critical use-after-free vulnerability in Samsung’s KNOX Process Authenticator (PROCA) within the FIVE integrity engine that affects Galaxy devices from S9 through S25 and some A-series devices across Exynos and Qualcomm variants. The flaw allows memory leaks, a constrained write primitive, and an attempted arbitrary call primitive (limited by Android KCFI), potentially enabling kernel-level memory corruption and complete device takeover; Samsung issued a fix in the January 2026 security update and users should ensure their devices are patched to 2026-01-01 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.