ZeroHour

CVE-2026-21102

large

Use-after-free in Samsung DualDAR allows local root code execution on Galaxy devices

CVSS 4.0
9.3 critical
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-21102 is a use-after-free vulnerability in Samsung's DualDAR (Dual Data-at-Rest), the Knox enterprise encryption component used on Galaxy devices in managed enterprise and government deployments. An attacker who already has privileged local access on the device can trigger the flaw in DualDAR and execute arbitrary code with root privileges, gaining full control of the device's encrypted data environment. Affected devices are Samsung Galaxy units where DualDAR is enabled and whose software predates the SMR Sep-2026 Release 1 security maintenance release. The flaw is rated critical (CVSS 4.0: 9.3) because the impact is full compromise (confidentiality, integrity, and availability all high), though exploitation requires local access with high privileges and no user interaction. There are currently no reports of in-the-wild exploitation, no known public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Update affected Galaxy devices to SMR Sep-2026 Release 1 (the September 2026 Samsung security maintenance release) or later, prioritizing enterprise and government fleets where DualDAR is enabled. Use Knox/MDM tooling to inventory devices' current security patch level and confirm whether DualDAR is provisioned, and restrict untrusted local privileged access (e.g., ADB, third-party device-management agents) on unpatched devices. No workarounds are documented; applying the SMR update is the primary mitigation.

Affected
Samsung DualDAR (Dual Data-at-Rest, Knox component on Samsung Galaxy devices)prior to SMR Sep-2026 Release 1
Estimated exposure
largelikely on the order of 100k–1M DualDAR-enabled Galaxy devices (estimate) — DualDAR is an optional Knox enterprise/government encryption feature on Galaxy Enterprise Edition devices with no publicly disclosed adoption counts, so this estimate assumes only a small subset of Samsung's very large Galaxy fleet is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

Vendors
samsung
Products
android
Weakness
CWE-416
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.