Impact
Improper authorization in KnoxGuardManager prior to SMR Feb‑2026 Release 1 permits local attackers to override the persistence configuration of the application. By manipulating this setting, an attacker can change how the app is maintained on the device, potentially granting themselves elevated privileges or enabling malicious code to survive reboot without user consent, effectively bypassing application authorization controls.
Affected Systems
Samsung Mobile Devices running Android 13, 14, 15, and 16 as listed in the CPE strings. The flaw is present in all SMR releases up to SMR Feb‑2026 Release 1 for each Android major version, covering a broad set of devices.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate‑level severity, while the EPSS score of less than 1 % shows low likelihood of exploitation. The vulnerability is not in CISA’s KEV catalog. Attackers must have local or physical access to the device, so the attack vector is inferred to be local. No remote exploitation path is documented, limiting the risk to environments where an adversary can gain device‑level control.
OpenCVE Enrichment