www.securityweek.com 6/23/2026, 1:35:40 PM · external

Eight Year Old Samsung KNOX Flaw CVE-2026-20971 Patched

Eight Year Old Samsung KNOX Flaw CVE-2026-20971 Patched
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

RESEARCHERS identified a high-severity, eight-year-old vulnerability in the KNOX kernel of Samsung devices, affecting models from Galaxy S9 to S25 (CVE-2026-20971, CVSS 7.8). The flaw arises from a race condition that could be exploited via an untrusted app, potentially leading to kernel memory corruption. Samsung addressed this issue in their January 2026 update.

Although initially considered locally exploitable, the risk exists that attackers could exploit it to gain control over devices, prompting a need for vigilance and security updates by users.

View Primary Source Via www.securityweek.com

Article by CyberSIXT