Exposure of Sensitive Information Vulnerability in Samsung Account
CVE-2022-30732
5.5MEDIUM
Summary
The Samsung Account application, prior to version 13.2.00.6, contains a vulnerability that enables unauthorized access to sensitive user information. This vulnerability occurs through the onActivityResult method, which may be exploited by attackers to extract data without proper authorization. Users of affected versions are encouraged to update their applications to safeguard their sensitive information from potential breaches.
Affected Version(s)
Samsung Account < 13.2.00.6
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved