Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks
2026-06-23T13:24:06Z•31b78528c6a8ce4b7cb17dadfd9f4226b9b308844705ac5be8cfa01e425a1fa7
androidcredentials-theftcybercrime-marketplacedata-breachexecutive-orderffmpegfortibleedinitial-access-brokerkernel-exploitknoxlibavcodecmarket0daypixelsmashpost-quantumpqcrcesamsungspoxysquidsquidbleeduse-after-free
What happened
Multiple high-impact security stories: an eight-year-old use-after-free flaw in Samsung KNOX (affecting Galaxy S9 through S25) could enable kernel-level attacks on millions of Android devices; a new FFmpeg “PixelSmash” vulnerability in libavcodec allows remote code execution in any application that uses FFmpeg (video players, media servers, NAS); a decades-old Squid proxy flaw dubbed “Squidbleed” can expose user data; a Russian initial-access broker using a custom sniffer has harvested 110+ million credentials in the FortiBleed campaign; several data breaches disclosed (Xsolis affecting ~1.4M,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 31b78528c6a8ce4b7cb17dadfd9f4226b9b308844705ac5be8cfa01e425a1fa7
- Enrichment time
- 2026-06-23T13:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.