Improper Access Control Vulnerability in Samsung Gallery for Samsung Devices
CVE-2022-33706
2.4LOW
Summary
An improper access control vulnerability exists in Samsung Gallery, which could allow attackers with physical access to the device to manipulate S Pen air gestures and gain access to photos stored on the device. This flaw poses a risk, especially in scenarios where users inadvertently leave their devices unattended, enabling unauthorized users to exploit the vulnerability and view sensitive images.
Affected Version(s)
Samsung Gallery < 13.1.05.8
References
CVSS V3.1
Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved