Improper Access Control in Samsung Android Devices
CVE-2022-36865

4MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
9 September 2022

Summary

A vulnerability exists in certain Samsung Android devices due to improper access control in the Group Sharing feature. This flaw allows unauthorized attackers to access sensitive device information, potentially compromising user privacy and security. The issue affects specific versions of the Android S and Android R operating systems, emphasizing the need for users to update their devices to the latest versions to mitigate the risk.

Affected Version(s)

Group Sharing < 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.