CVE Tools

MEGANews. Cамые важные события в мире инфосека за июнь

Хакер (xakep.ru)By Мария Нефёдова

IncidentApp StoreVK Apps

Our summary

Researchers reported a long-standing vulnerability in Samsung Knox affecting multiple Galaxy generations, where an unprivileged app could trigger a use-after-free leading to kernel memory corruption; the issue is tracked as CVE-2026-20971 and was fixed in January 2026. In parallel, Apple removed VK and MAX apps from the App Store, while sources for the Miasma worm were published after being exposed via compromised development accounts. These events matter because they underline both ongoing supply-chain malware risks and persistent privilege/escalation paths in widely deployed mobile security frameworks.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store