Improper Access Control Vulnerability in Samsung Gallery for Samsung Devices
CVE-2022-33706

2.4LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
12 July 2022

Summary

An improper access control vulnerability exists in Samsung Gallery, which could allow attackers with physical access to the device to manipulate S Pen air gestures and gain access to photos stored on the device. This flaw poses a risk, especially in scenarios where users inadvertently leave their devices unattended, enabling unauthorized users to exploit the vulnerability and view sensitive images.

Affected Version(s)

Samsung Gallery < 13.1.05.8

References

CVSS V3.1

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.