Eight Years Undetected

Millions of Samsung Devices Exposed to Kernel Attacks

Mobile Security, Samsung KNOX vulnerability, Samsung Galaxy security, CVE-2026-20971, Samsung KNOX vulnerability affecting Galaxy devices, samsung galaxy vulnerability, Samsung, Cyber Security
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Framesira / Shutterstock.com

A security flaw in Samsung’s KNOX framework that remained undiscovered for years put millions of Galaxy devices at risk of potential kernel-level attacks.

Security researchers at LucidBit Labs have identified an eight-year-old high-severity vulnerability in the Samsung KNOX security kernel. The flaw is tracked as CVE-2026-20971 and has a CVSS base score of 7.8. It stems from an improper interaction between the internal subsystems PROCA (Process Authenticator) and FIVE (Integrity Subsystem). PROCA monitors the authenticity of running processes within the kernel and relies on security states managed by FIVE. When a process undergoes a change, such as spawning a child process, the previous integrity structure is released.

Ad

Due to the preemptive nature of the Android kernel, this creates a brief window for a race condition that can result in a use-after-free vulnerability. A thread can be paused at exactly the point between reading a pointer and using it. The researchers describe the technical process as follows:

“The target task executes “execve()“, specifically “task_integrity_put(old_tint)“, which frees the original structure. “proc_integrity_value_read()” resumes execution and calls “task_integrity_user_read()” with a pointer to freed memory.”

LucidBit Labs security researchers

Ad

Affected Samsung Galaxy Models and Security Updates

Although the kernel-integrated Kernel Control Flow Integrity (KCFI) made arbitrary function calls more difficult, the analysts found a way to manipulate the freed memory by loading a non-executable file. This bypassed existing reference counter restrictions and enabled controlled memory reallocation. As a result, an untrusted application could trigger kernel memory corruption, potentially allowing deeper system privileges to be compromised.

The vulnerability affected millions of mobile devices across multiple generations. Impacted models include the Galaxy S9 through Galaxy S25 series, various Galaxy A-series devices, as well as models powered by Exynos and Qualcomm processors running Android versions 13, 14, 15, and 16.

Samsung addressed the issue with its January 2026 security update. Since exploitation primarily requires local interaction, the researchers emphasize that physical access to temporarily unattended devices represented the main attack risk.

(ll)

Ad

Artikel zu diesem Thema

Weitere Artikel