Samsung KNOX Kernel UAF Exposes Millions of Galaxy Devices

2026-06-24T08:52:44Z0bee508901ba662487b4f7d22b99a6207fb9e9fdf2fba1d0bb9cbf605ad61b18
2FA compromiseAI platformCVE-2026-20971CVE-2026-47729DifyDifyTapFortiBleedFortiGate devices','AryStinger','router compromise','IoT/edge','Samsung KNOXShapedPluginSquid ProxySquidbleedTexas Parks & WildlifeWhatsApp malwareXsoliscredential harvestingcredential theftcross-tenant data exposuredata breachhealthcare breachkernel UAFphishingplugin backdoorremote access toolsupply chain compromise

What happened

Multiple high-impact security incidents and vulnerabilities reported: a Samsung KNOX kernel use-after-free (CVE-2026-20971) impacting millions of Galaxy devices; ‘DifyTap’ (Dify) disclosed four vulnerabilities (two rated critical) allowing cross-tenant data exposure and unauthenticated access to AI apps; Squidbleed (CVE-2026-47729) — a decades-old Squid proxy memory leak — can expose credentials and tokens. Several large breaches and active campaigns were detailed: Xsolis (1.4M individuals) and Texas Parks & Wildlife (3M) data breaches tied to phishing/third-party compromise; FortiBleed mass-­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0bee508901ba662487b4f7d22b99a6207fb9e9fdf2fba1d0bb9cbf605ad61b18
Enrichment time
2026-06-24T08:52:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Samsung KNOX Kernel UAF Exposes Millions of Galaxy Devices · Baitaphish