Implicit Intent Hijacking Vulnerability in Samsung Account
CVE-2022-30737

4MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
7 June 2022

Summary

An Implicit Intent hijacking vulnerability exists in Samsung Account that could allow an attacker to gain unauthorized access to a user's email ID. This security flaw, present in versions before 13.2.00.6, puts user data at risk by enabling malicious actors to exploit the intent system on affected devices. Users should ensure they update to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

Samsung Account < 13.2.00.6

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.