Samsung KNOX Use-After-Free Bug Sat in Galaxy Devices for Eight Years Before Patch
A high-severity kernel-level flaw in Samsung's KNOX security framework affected Galaxy handsets from the S9 through the S25 — a product window spanning nearly a decade.

Eight years is a long time for a flaw to live inside a security framework whose entire pitch is protecting sensitive device data.
The vulnerability is a use-after-free bug in Samsung's KNOX framework, rated high severity. Use-after-free flaws occur when a program continues to reference memory after freeing it; on Android, that class of bug can hand an attacker a path straight to the kernel. That is not a theoretical risk — kernel-level access means full device compromise: reading encrypted storage, bypassing KNOX containers, intercepting communications.
The affected hardware spans Samsung Galaxy S9 through S25 models. Samsung ships tens of millions of Galaxy units annually, so the exposure window across that device range runs into the hundreds of millions of handsets worldwide.
Samsung has not published a detailed advisory that names a CVE identifier in publicly accessible form as of this writing. When Samsung does assign one, the canonical record will appear at the NVD. Threat Vectr will update this piece when that filing is live.
Jurisdiction over breach and vulnerability disclosure obligations here is diffuse. In the United States, the FTC has broad authority over unfair or deceptive security practices. South Korea's Personal Information Protection Commission (PIPC) governs Samsung's domestic obligations. If KNOX containers held enterprise data belonging to EU residents, Article 32 of GDPR pulls the ICO and other EU supervisory authorities into scope as well.
What made this particularly uncomfortable is where it sat. KNOX markets itself as the defense layer — Samsung's answer to enterprise MDM concerns, government certification requirements, and Knox Vault hardware isolation. A use-after-free in that specific component is not a bug in a peripheral feature. It is a crack in the load-bearing wall.
Samsung's monthly Android security bulletin is the place to watch for patch status and scope details.
What affected users should do
First, check your Samsung device's security patch level under Settings > About phone > Software information. Install any pending Samsung security updates immediately — do not defer. Enterprise administrators managing Galaxy fleets through MDM platforms should force a patch compliance check and flag unpatched devices as non-compliant pending remediation. If your organization uses KNOX containers for regulated or sensitive data, review access logs for anomalous activity covering the period before patch deployment.



