Improper Access Control in Samsung Members Application
CVE-2022-28777
4.3MEDIUM
What is CVE-2022-28777?
An improper access control vulnerability exists in the Samsung Members application, allowing a local attacker to execute call functions without the necessary CALL_PHONE permissions. This flaw affects versions prior to 13.6.08.5, posing a risk to users due to potential unauthorized call actions. It is essential for users of the Samsung Members app to update to the latest version to mitigate this vulnerability.
Affected Version(s)
Samsung Members - < 13.6.08.5