Intent Hijacking Vulnerability in Bixby Vision by Samsung
CVE-2022-23434
4.4MEDIUM
Summary
A security vulnerability in Bixby Vision allows attackers to hijack PendingIntent actions, enabling the execution of privileged operations. This affects versions prior to 3.7.60.8 on Android S (12) and prior to 3.7.50.6 on Android R (11) and below. Attackers may exploit this flaw by manipulating intents, potentially leading to unauthorized access and actions within the app, emphasizing the need for users to update their applications to secure versions to mitigate risks.
Affected Version(s)
Bixby Vision - < 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved