Unprotected Component in Samsung Galaxy S3/S4 Exposes SMS Vulnerability
CVE-2013-4764

4.3MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
27 December 2019

Summary

A vulnerability found in the Samsung Galaxy S3 and S4 smartphones allows an unprivileged application to utilize an unprotected component. This flaw enables the app to send SMS messages to any destination without the user's permission. This unauthorized access could lead to significant privacy concerns and unauthorized charges for users, making it crucial for Samsung to address this issue.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.