Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    This Week’s Awesome Tech Stories From Around the Web (Through August 1)

    August 1, 2026

    Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal

    August 1, 2026

    The Man Who Understood Risk: Robert N. Charette retires.

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • This Week’s Awesome Tech Stories From Around the Web (Through August 1)
    • Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
    • The Man Who Understood Risk: Robert N. Charette retires.
    • 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World
    • This AI Assistant Wants to Make Up for Your Boyfriend’s Incompetence
    • Europe Approves Bionic Eye to Restore Vision Lost to Blindness
    • Chinese AI Researchers Are Finding Their Voice on X
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks
    Cybersecurity

    Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 24, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Samsung KNOX Vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Researchers found an eight-year old high severity vulnerability affecting nearly all Samsung devices from the Galaxy S9 to S25 living within the KNOX kernel.

    The flaw (CVE‑2026‑20971, CVSS 7.8) could be exploited through the interaction between PROCA and FIVE. PROCA, the process authenticator, is a proprietary subsystem in the kernel of the Samsung devices designed to prevent unauthorized processes from executing. It validates process authenticity using FIVE, the kernel side integrity subsystem, based on the Linux integrity-measurement model and extended by Samsung.

    FIVE tracks trust in each running process, applying a task_integrity object that records its security state. If the process changes, perhaps it forks a child, the child invokes execve() which triggers a new integrity and drops the old one. This should be instantaneous – but enter Android’s preemptive Kernel within which it all runs. The net effect is a tiny window which, if reachable, is a classic race-condition use-after-free (UAF) target. 

    Because of the preemptive kernel, a thread can be suspended between reading the pointer and using it. “The target task executes execve(), specifically task_integrity_put(old_tint), freeing the original struct. proc_integrity_value_read() resumes and calls task_integrity_user_read() with a pointer to freed memory,” reports the LucidBit Labs researchers who discovered the flaw.

    The researchers do not suggest that exploiting this UAF was easy, only that it was possible. The built-in kernel control flow integrity (KCFI) made it almost impossible, but not quite. It didn’t eliminate the UAF but closed down arbitrary function calls which are the most dangerous exploitation path.

    However, these researchers found a way to exploit the UAF by getting the process to ‘load’ a file that could not be executed; that is, a non-ELF file. “This removes the reset_file refcount > 1 blocker,” they explain. A few more tricks and they could “Reallocate the freed memory in a fully controlled manner.”

    Advertisement. Scroll to continue reading.

    In the end, the researchers found a way. LucidBit Labs says the flaw could be triggered from an untrusted app and could lead to kernel memory corruption, potentially giving an attacker a path toward deeper control of the device.

    The researchers disclosed their findings to Samsung, and Samsung fixed the problem in its January 2026 update. This issue existed across multiple Samsung device generations, including Galaxy S9 through Galaxy S25, A-series devices, and both Exynos- and Qualcomm-based models. Samsung’s advisory lists affected versions as Android 13, 14, 15, and 16.

    It states, “Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.”

    On the surface, this vulnerability was only exploitable locally, which would suggest that it was not that dangerous. But that’s ‘user’ interaction, not necessarily ‘legitimate owner’ interaction. Very few mobile device users have not mislaid their device only to find it again a day later. The assumption is just that we forgot where we put it – but nobody knows for certain where it was or who could have handled it during that time. 

    In the wider cybercrime ecosphere, getting a remote access foothold into an always-on device is a common practice. Attackers have numerous ways of getting around local exploitability. If the vulnerability had allowed an attacker to gain control of a staff mobile device, the attacker could potentially pivot onto the enterprise network. Although resolved by Samsung in January, it is important to ensure your own device has been patched. 

    But perhaps the biggest take-away from this research is that defenders must treat their own security stack as a potential attack surface that can be exploited by adversaries.

    Related: Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

    Related: Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities

    Related: Mobile Attack Surface Expands as Enterprises Lose Control

    Related: Landfall Android Spyware Targeted Samsung Phones via Zero-Day

    Attacks devices EightYearOld exposed Flaw Galaxy Kernel KNOX millions Samsung
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    A fundamental flaw leaves LLMs strikingly vulnerable to attack

    July 31, 2026

    Private Claude Chats Exposed in Google and Bing Search Results

    July 27, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • This Week’s Awesome Tech Stories From Around the Web (Through August 1)
    • Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
    • The Man Who Understood Risk: Robert N. Charette retires.
    • 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World

    This Week’s Awesome Tech Stories From Around the Web (Through August 1)

    August 1, 2026

    Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal

    August 1, 2026

    The Man Who Understood Risk: Robert N. Charette retires.

    August 1, 2026

    7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

    August 1, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.