ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21102
Use-after-free in Samsung DualDAR allows local root code execution on Galaxy devices

CVE-2026-21102 is a use-after-free vulnerability in Samsung's DualDAR (Dual Data-at-Rest), the Knox enterprise encryption component used on Galaxy devices in managed enterprise and government deployments. An attacker who already has privileged local access on the device can trigger the flaw in DualDAR and execute arbitrary code with root privileges, gaining full control of the device's encrypted data environment. Affected devices are Samsung Galaxy units where DualDAR is enabled and whose software predates the SMR Sep-2026 Release 1 security maintenance release. The flaw is rated critical (CVSS 4.0: 9.3) because the impact is full compromise (confidentiality, integrity, and availability all high), though exploitation requires local access with high privileges and no user interaction. There are currently no reports of in-the-wild exploitation, no known public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Update affected Galaxy devices to SMR Sep-2026 Release 1 (the September 2026 Samsung security maintenance release) or later, prioritizing enterprise and government fleets where DualDAR is enabled. Use Knox/MDM tooling to inventory devices' current security patch level and confirm whether DualDAR is provisioned, and restrict untrusted local privileged access (e.g., ADB, third-party device-management agents) on unpatched devices. No workarounds are documented; applying the SMR update is the primary mitigation.

9.3
group max
<1%
  • Samsung DualDAR (Dual Data-at-Rest, Knox component on Samsung Galaxy devices) prior to SMR Sep-2026 Release 1
largelikely on the order of 100k–1M DualDAR-enabled Galaxy devices (estimate)