Samsung KNOX Use-After-Free Bug Sat in Galaxy Devices for Eight Years Before Patch
A high-severity kernel-level flaw in Samsung's KNOX security framework affected Galaxy handsets from the S9 through the S25, a product window spanning nearly a decade.

Key points
- A use-after-free bug in Samsung's KNOX security framework affected Galaxy S9 through S25 devices.
- The flaw is rated high severity and can give an attacker kernel-level access, meaning full device compromise.
- Samsung has not published a CVE identifier in publicly accessible form as of this writing.
- Enterprise admins running Galaxy fleets via MDM should force a patch compliance check now.
- Samsung's monthly Android security bulletin is the place to watch for patch scope and status.
Eight years is a long time for a flaw to live inside a security framework whose entire pitch is protecting sensitive device data.
What is the vulnerability?
The bug is a use-after-free: a program keeps referencing memory after it's been freed. On Android, that class of flaw can hand an attacker a direct path to the kernel. Kernel access isn't theoretical. It means reading encrypted storage, bypassing KNOX containers, and intercepting communications.
The affected hardware runs from the Galaxy S9 through the S25. Our June 2026 Android bulletin coverage showed how quickly a kernel-adjacent Android flaw can move from patch to active exploitation, which makes the eight-year window here hard to look past.
Where does the legal exposure fall?
Jurisdiction is diffuse. The FTC holds broad authority over unfair or deceptive security practices in the United States. South Korea's Personal Information Protection Commission governs Samsung's domestic obligations. Where KNOX containers held enterprise data belonging to EU residents, GDPR pulls EU supervisory authorities into scope as well.
Should you worry about KNOX specifically?
Yes, and here's why: the discomfort isn't just the bug's age. KNOX markets itself as the defense layer, Samsung's answer to enterprise mobile-device-management concerns and government certification requirements. A use-after-free in that component isn't a crack in a peripheral feature. It's a crack in the load-bearing wall. That distinction matters when procurement teams and regulators ask why certified devices were carrying a high-severity kernel flaw across a decade of hardware generations.
Samsung has not published a detailed advisory naming a CVE identifier in publicly accessible form as of this writing. When one is assigned, the canonical record will appear at the NVD, and Threat Vectr will update this piece.
What affected users should do
Check your Samsung device's security patch level under Settings > About phone > Software information and install any pending updates. Don't defer. Enterprise administrators managing Galaxy fleets should force a patch compliance check and flag unpatched devices as non-compliant. If your organisation uses KNOX containers for regulated or sensitive data, review access logs for anomalous activity covering the period before patch deployment.



