[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhYQ1AKcuHyCdKqGDO17I33NEoU8kh1Mfu_LJhm7kLqg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"9f9f4c37-341b-4f0b-99b1-06c3e9d47a87","eight-year-old-samsung-knox-kernel-flaw-left-millions-of-galaxy-devices-exposed","0e523ad3-163f-4d21-9d22-c91c99657b21","Eight-Year-Old Samsung KNOX Kernel Flaw Left Millions of Galaxy Devices Exposed","A use-after-free vulnerability that sat undetected in Samsung's KNOX kernel for eight years highlights the dangers of aging code in widely deployed consumer and enterprise devices. Despite existing mitigations like kernel control flow integrity (kCFI), researchers identified a novel exploitation path using non-executable files, demonstrating that mitigations alone are not a substitute for patching. The flaw affected a massive range of devices — from the Galaxy S9 to the S25 — meaning millions of users were potentially exposed throughout the vulnerability's lifespan. This case underscores how long-lived vulnerabilities in trusted security frameworks (like KNOX) can erode the very protection they are meant to provide, and why proactive vulnerability research and timely patch cycles are critical.","**Immediate actions:**\n- Apply Samsung's January 2026 security update to all affected Galaxy devices as soon as possible.\n- Enroll all managed mobile devices in an MDM\u002FEMM platform to enforce and verify patch compliance across the fleet.\n\n**Long-term improvements:**\n- Establish a structured mobile device patch management policy with defined SLAs for critical and high-severity vulnerabilities.\n- Conduct regular audits of third-party security frameworks (e.g., KNOX, Secure Enclave equivalents) as part of the broader vulnerability management program.\n- Engage in or subscribe to vendor security advisories and CVE feeds to detect newly disclosed vulnerabilities before they are exploited in the wild.\n\n**Detection measures:**\n- Deploy mobile threat defense (MTD) solutions capable of detecting kernel-level exploitation attempts on managed endpoints.\n- Monitor device compliance dashboards for devices running outdated firmware or security patch levels and trigger automated remediation workflows.",[12,13,14,15,16,17,18,19],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST SP 800-124: Guidelines for Managing the Security of Mobile Devices in the Enterprise","NIST CSF ID.VM-1: Vulnerabilities in assets are identified and documented","ISO\u002FIEC 27001:2022 A.8.8: Management of technical vulnerabilities","ITIL 4: Change Enablement and Problem Management practices","published","2026-06-23T15:21:10.783365+00:00","2026-06-23T15:21:10.683+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.securityweek.com\u002Feight-year-old-samsung-knox-flaw-exposed-millions-of-galaxy-devices-to-kernel-attacks\u002F","eight-year-old-samsung-knox-flaw-exposed-millions-of-galaxy-devices-to-kernel-at-f49d72","Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]