Executive brief
A security vulnerability exists in Samsung's KnoxGuardManager, a component used for device security and management. A local attacker could exploit this flaw to bypass security configurations that are intended to remain persistent on the device. This could allow unauthorized changes to device management settings or the removal of security restrictions.
Technical details
An improper authorization vulnerability exists in the KnoxGuardManager component of Samsung mobile devices running Android 14, 15, and 16. The flaw allows a local attacker with low privileges to bypass persistence configurations, which are typically used to ensure security policies survive reboots or factory resets. The root cause is a failure to correctly enforce authorization checks within the KnoxGuard service. Successful exploitation could lead to the modification of high-integrity security settings. This issue is addressed in the Samsung SMR Jul-2026 Release 1 update.
Affected products
- Samsung Mobile Samsung Mobile Devices (Android 14, 15, 16) Prior to SMR Jul-2026 Release 1
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory