Improper Access Control in Wear OS 3.0 by Samsung Electronics
CVE-2022-23994
3.3LOW
What is CVE-2022-23994?
An improper access control vulnerability exists in the StBedtimeModeReceiver component of Wear OS 3.0 software. This flaw allows untrusted applications to alter bedtime mode settings without sufficient permissions, potentially compromising user configuration and exposing devices to unauthorized modifications. Users are advised to update to the latest firmware version released in February 2022 to mitigate this issue.
Affected Version(s)
Samsung Wearable Devices Wear OS 3.0