Impact
Improper authorization in KnoxGuardManager allows a local attacker to change the application’s persistence settings without proper permissions. This is an access‑control weakness, where the authorization check is bypassed when configuring how the application stores its state. The attacker could thus alter persistence behavior, potentially enabling unauthorized data retention or change of application state.
Affected Systems
Samsung Mobile Devices running firmware that includes KnoxGuardManager before the SMR Jul‑2026 Release 1 update remain impacted. Devices that have not applied the July 2026 security patch are vulnerable.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity, and the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access to the device, as the attacker must manipulate the persistence configuration through the KnoxGuardManager interface. Consequently, the risk is moderate but the probability of exploitation is low, yet timely remediation is advisable to prevent future abuse.
OpenCVE Enrichment