Improper Access Control in Samsung Android Devices
CVE-2022-36865
4MEDIUM
Summary
A vulnerability exists in certain Samsung Android devices due to improper access control in the Group Sharing feature. This flaw allows unauthorized attackers to access sensitive device information, potentially compromising user privacy and security. The issue affects specific versions of the Android S and Android R operating systems, emphasizing the need for users to update their devices to the latest versions to mitigate the risk.
Affected Version(s)
Group Sharing < 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below
References
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved