Improper Access Control in Wear OS 3.0 by Samsung Electronics
CVE-2022-23994

3.3LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
11 February 2022

Summary

An improper access control vulnerability exists in the StBedtimeModeReceiver component of Wear OS 3.0 software. This flaw allows untrusted applications to alter bedtime mode settings without sufficient permissions, potentially compromising user configuration and exposing devices to unauthorized modifications. Users are advised to update to the latest firmware version released in February 2022 to mitigate this issue.

Affected Version(s)

Samsung Wearable Devices Wear OS 3.0

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.