Package
com.samsung.android.kmxservice
Knox Matrix
Guidance
Shown on the device as "Knox Matrix", this is Samsung's on-device service for Knox Matrix, the company's cross-device security feature. Samsung's own Galaxy Store listing for this package name describes Knox Matrix as a secure cross-device platform for connecting and using the devices signed in to your Samsung account. Knox Matrix works through Trust Chain, described by Samsung as a secure private blockchain in which connected devices monitor each other for threats: if a device is flagged as seriously at risk, Knox Matrix isolates it from the group and the dashboard offers a recommended action. In our sample it is signed by a Samsung OEM key that also signs the Android framework, a platform-level key. It is a background service with no launcher entry of its own. Samsung's support documentation places the user-facing side under Settings, in the security and privacy section as the device security status view, and also reachable from the SmartThings app. The devices being watched must all be signed in to the same Samsung account, and Samsung documents support for up to 32 compatible devices. For Android Enterprise, EMM and kiosk work the important point is that this is a consumer ecosystem feature keyed to a personal Samsung account, not an enterprise management channel. It is not the Knox Zero Trust Framework and not Knox Platform for Enterprise, both documented separately, and an EMM does not use it to apply policy. On a corporate device with no Samsung account signed in there is little for it to do, but it is still a security component and Samsung does not document the effect of disabling it, so treat it as caution and test rather than removing it as routine cleanup. Version note: Samsung documents the device security status view as requiring One UI 7 or later on Galaxy phones and tablets, with Samsung TVs, monitors and appliances needing software released after 2025, and the Knox Matrix dashboard was presented as a One UI 7 addition. Behaviour on earlier builds therefore differs, and this package was first recorded on this site in June 2025. Whether the service does anything on a device running an older One UI could not be sourced.
- Knox Matrix (com.samsung.android.kmxservice) - Samsung Galaxy Store listing →
- Ver estado de seguridad de tus dispositivos con Knox Matrix (viewing your devices' security status with Knox Matrix) - Samsung Latin America support →
- Samsung One UI 7 Enhances Security and Privacy in the Age of AI - Samsung Mobile Press →
- Package provenance for com.samsung.android.kmxservice - Android System App Database →
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Signed by the device maker's own signing key (Samsung), so it is an OEM preinstall, and that single certificate is consistent across all 18 device profiles. It also signs the Android framework, so it is a platform-level key on its device(s). Inferred from the certificate appearing only on Samsung devices (508 packages, 10196 observations).
- Its largest observed manifest declares 73 permissions: 1 runtime (user-granted), 8 signature or system-level, 7 install-time and 57 vendor or uncatalogued.
- APK size ranges from 20.1 MB to 45.8 MB across the reporting device profiles, so the build differs substantially between them.
- Reported as an updated system app on 12 of 18 profiles - a newer build is installed over the one in the system image there.
Declared permissions (73)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
ACCESS_KEYGUARD_SECURE_STORAGE |
Signature-level system permission, for platform-signed apps. |
ACCESS_LOCAL_NETWORK |
- |
ACCESS_NETWORK_STATE |
Allows the app to view information about network connections such as which networks exist and are connected. |
BATTERY_STATS |
Signature or privileged system permission. |
FOREGROUND_SERVICE |
Allows the app to make use of foreground services. |
INTERACT_ACROSS_USERS_FULL |
Signature-level system permission, for platform-signed apps. |
INTERNAL_SYSTEM_WINDOW |
Signature-level system permission, for platform-signed apps. |
INTERNET |
Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. |
POST_NOTIFICATIONS |
Allows the app to show notifications |
QUERY_ALL_PACKAGES |
Allows an app to see all installed packages. |
RECEIVE_BOOT_COMPLETED |
Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the phone and allow the app to slow down the overall phone by always running. |
REQUEST_PASSWORD_COMPLEXITY |
Allows the app to learn the screen lock complexity level (high, medium, low or none), which indicates the possible range of length and type of the screen lock. The app can also suggest to users that they update the screen lock to a certain level but users can freely ignore and navigate away. Note that the screen lock is not stored in plaintext so the app does not know the exact password. |
REVOKE_RUNTIME_PERMISSIONS |
Signature-level system permission, for platform-signed apps. |
START_ACTIVITIES_FROM_BACKGROUND |
Signature or privileged system permission. docs ↗ |
WAKE_LOCK |
Allows the app to prevent the phone from going to sleep. |
WATCH_APPOPS |
Signature or privileged system permission. |
WRITE_SECURE_SETTINGS |
Signature or privileged system permission. |
com.google.android.c2dm.permission.RECEIVE |
- |
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE |
- |
com.google.android.gms.permission.AD_ID |
- |
com.samsung.android.aicore.permission.BIND_DOWNLOAD_SERVICE |
- |
com.samsung.android.aicore.permission.BIND_ON_DEVICE_SERVICE |
- |
com.samsung.android.aicore.permission.BIND_WALLPAPER_SERVICE |
- |
com.samsung.android.aicore.permission.SUPPORTED_FEATURE_PROVIDER |
- |
com.samsung.android.intellivoiceservice.ai.asr.permission.BIND_SPEECH_RECOGNITION_SERVICE |
- |
com.samsung.android.intellivoiceservice.ai.asr.permission.SPEECH_RECOGNITION_SERVICE_CONFIG_PROVIDER |
- |
com.samsung.android.intellivoiceservice.ai.asr.permission.SYSTEM_BIND_SPEECH_RECOGNITION_SERVICE |
- |
com.samsung.android.intellivoiceservice.ai.asr.permission.SYSTEM_SPEECH_RECOGNITION_SERVICE_CONFIG_PROVIDER |
- |
com.samsung.android.intellivoiceservice.aitranslator.permission.BIND_TRANSLATION |
- |
com.samsung.android.intellivoiceservice.aitranslator.permission.BIND_TRANSLATION_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.common.permission.CONFIG_PROVIDER |
- |
com.samsung.android.intellivoiceservice.common.permission.SYSTEM_CONFIG_PROVIDER |
- |
com.samsung.android.intellivoiceservice.permission.BIND_CLASSIFICATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_CONFIGURATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_CORRECTION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_EMOJI_AUGMENTATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_EXTRACTION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_FORMAT_CONVERSION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_GENERIC_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_NOTES_ORGANIZATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SMART_CAPTURE_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SMART_COVER_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SMART_REPLY_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SUGGESTION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SUGGESTION_SERVICE_FOR_EXTERNAL |
- |
com.samsung.android.intellivoiceservice.permission.BIND_SUMMARIZATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_TONECONVERT_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_TRANSLATION_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_USAGE_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.BIND_WRITING_COMPOSER_SERVICE |
- |
com.samsung.android.intellivoiceservice.permission.SUPPORTED_FEATURE_PROVIDER |
- |
com.samsung.android.kmxservice.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION |
- |
com.samsung.android.kmxservice.permission.KMX_E2EE_SERVICE |
- |
com.samsung.android.launcher.permission.READ_SETTINGS |
- |
com.samsung.android.permission.READ_SCPM |
- |
com.samsung.android.permission.WRITE_SCPM |
- |
com.samsung.android.samsungaccount.permission.ACCOUNT_MANAGER |
- |
com.samsung.android.scs.ai.asr.permission.BIND_SPEECH_RECOGNITION_SERVICE |
- |
com.samsung.android.scs.ai.asr.permission.SPEECH_RECOGNITION_SERVICE_CONFIG_PROVIDER |
- |
com.samsung.android.scs.ai.asr.permission.SYSTEM_BIND_SPEECH_RECOGNITION_SERVICE |
- |
com.samsung.android.scs.ai.asr.permission.SYSTEM_SPEECH_RECOGNITION_SERVICE_CONFIG_PROVIDER |
- |
com.samsung.android.scs.ai.image.permission.BIND_IMAGE_SERVICE |
- |
com.samsung.android.scs.ai.image.permission.IMAGE_PROVIDER |
- |
com.samsung.android.scs.ai.suggestion.permission.SUGGESTION_PROVIDER |
- |
com.samsung.android.scs.ai.text.permission.TEXT_PROVIDER |
- |
com.samsung.android.scs.permission.SUPPORTED_FEATURE_PROVIDER |
- |
com.samsung.android.security.permission.SAMSUNG_KEYSTORE_PERMISSION |
- |
com.samsung.android.visual.cloudcore.permission.BIND_DOWNLOAD_SERVICE |
- |
com.samsung.android.visual.cloudcore.permission.BIND_IMAGE_EDITOR_SERVICE |
- |
com.samsung.android.visual.cloudcore.permission.BIND_PORTRAIT_SERVICE |
- |
com.samsung.android.visual.cloudcore.permission.SUPPORTED_FEATURE_PROVIDER |
- |
com.samsung.permission.LAUNCH_SOFTWARE_UPDATE |
- |
com.samsung.security.fabric.crypto.permission.KNOX_MATRIX |
- |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Samsung | SM-A135F | Android 14 | OEM Samsung | 3 | 21 Jan 2026 |
| Samsung | SM-A137F | Android 14 | - | 1 | 17 Jan 2026 |
| Samsung | SM-A236B | Android 14 | OEM Samsung | 2 | 10 Apr 2026 |
| Samsung | SM-A266B | Android 15 | - | 2 | 21 Aug 2025 |
| Samsung | SM-A266B | Android 16 | - | 1 | 26 Jan 2026 |
| Samsung | SM-A346B | Android 15 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-A536B | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 16 | OEM Samsung | 1 | 29 Jul 2026 |
| Samsung | SM-A556B | Android 15 | - | 1 | 1 Jul 2025 |
| Samsung | SM-A566B | Android 16 | OEM Samsung | 3 | 12 Sep 2026 |
| Samsung | SM-F721B | Android 15 | - | 1 | 9 Jul 2025 |
| Samsung | SM-F766B | Android 16 | - | 1 | 11 Nov 2025 |
| Samsung | SM-F971B | Android 17 | OEM Samsung | 1 | 18 Sep 2026 |
| Samsung | SM-G766B | Android 15 | - | 1 | 17 Oct 2025 |
| Samsung | SM-G766B | Android 16 | OEM Samsung | 1 | 5 Sep 2026 |
| Samsung | SM-G991B | Android 15 | OEM Samsung | 1 | 19 Apr 2026 |
| Samsung | SM-S721U | Android 15 | - | 5 | 5 Aug 2025 |
| Samsung | SM-S731B | Android 16 | OEM Samsung | 1 | 11 Aug 2026 |
| Samsung | SM-S906B | Android 15 | - | 1 | 2 Jun 2025 |
| Samsung | SM-S908U | Android 16 | OEM Samsung | 2 | 17 Sep 2026 |
| Samsung | SM-S921B | Android 15 | OEM Samsung | 2 | 22 Jul 2025 |
| Samsung | SM-S921B | Android 16 | OEM Samsung | 1 | 17 Sep 2026 |
| Samsung | SM-S921U | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-S926B | Android 16 | OEM Samsung | 1 | 14 Apr 2026 |
| Samsung | SM-S928B | Android 16 | OEM Samsung | 2 | 12 Jun 2026 |
| Samsung | SM-S928U1 | Android 15 | - | 1 | 12 Sep 2025 |
| Samsung | SM-S931B | Android 15 | - | 1 | 20 Sep 2025 |
| Samsung | SM-S931B | Android 16 | - | 1 | 23 Nov 2025 |
| Samsung | SM-S936B | Android 16 | - | 1 | 18 Dec 2025 |
| Samsung | SM-S937B | Android 15 | - | 1 | 25 Aug 2025 |
| Samsung | SM-S938B | Android 15 | - | 2 | 25 Aug 2025 |
| Samsung | SM-S942B | Android 17 | OEM Samsung | 1 | 25 May 2026 |
| Samsung | SM-S948U | Android 16 | - | 1 | 9 Sep 2026 |
| Samsung | SM-T636B | Android 15 | - | 2 | 12 Oct 2025 |
| Samsung | SM-T976B | Android 13 | - | 1 | 21 Jul 2025 |
| Samsung | SM-X716B | Android 15 | - | 1 | 27 Jun 2025 |
| Samsung | SM-X910 | Android 14 | - | 1 | 26 Jun 2025 |
| Samsung | SM-X910 | Android 15 | - | 1 | 12 Sep 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| Knox Matrix | en | 20 |
| Knox Matrix | en-gb | 18 |
| Knox Matrix | en-us | 17 |
| Knox Matrix | it-IT | 5 |
| Knox Matrix | nl-nl | 4 |
| Knox Matrix | en-nl | 3 |
| Knox Matrix | es-ES | 2 |
| Knox Matrix | es-es | 2 |
| Knox Matrix | it-it | 2 |
| Knox Matrix | de-de | 2 |
| Knox Matrix | en-GB | 2 |
| KmxService | en-gb | 1 |
| Knox Matrix | fr-fr | 1 |
| Knox Matrix | en-au | 1 |
| Knox Matrix | pl-PL | 1 |
| Knox Matrix | pl-pl | 1 |
| Knox Matrix | ru-ru | 1 |