Improper D-Bus Security in Tizen Affects Samsung Gear Series
CVE-2018-16263
8.8HIGH
What is CVE-2018-16263?
The PulseAudio system service on Tizen devices is subject to a vulnerability that allows unprivileged processes to gain control over the A2DP MediaEndpoint. This issue stems from inadequate D-Bus security policy configurations, which could potentially lead to unauthorized access and control over audio streaming functionalities. This vulnerability impacts various versions of Tizen, specifically those prior to 5.0 M1, and affects the Samsung Galaxy Gear series devices that were released before build RE2.