Implicit Intent Hijacking in UPHelper Library by Samsung
CVE-2022-39859

4MEDIUM

Key Information:

Vendor
Samsung
Status
Vendor
CVE Published:
7 October 2022

Summary

The UPHelper library prior to version 3.0.12 is susceptible to an implicit intent hijacking vulnerability. This weakness allows malicious actors to exploit the library, potentially accessing sensitive information by manipulating implicit intents. Such unauthorized access can compromise user data integrity, making it essential for developers to update to a more secure version promptly to mitigate risks associated with this vulnerability.

Affected Version(s)

UPHelper < 3.0.12

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.