Exposure of Sensitive Information Vulnerability in Samsung Account
CVE-2022-30732

5.5MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
7 June 2022

Summary

The Samsung Account application, prior to version 13.2.00.6, contains a vulnerability that enables unauthorized access to sensitive user information. This vulnerability occurs through the onActivityResult method, which may be exploited by attackers to extract data without proper authorization. Users of affected versions are encouraged to update their applications to safeguard their sensitive information from potential breaches.

Affected Version(s)

Samsung Account < 13.2.00.6

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.