Insufficient Data Authenticity Verification in Routine for Android Products by Samsung
CVE-2023-21441

7.4HIGH

Key Information:

Vendor

Samsung

Status
Vendor
CVE Published:
9 February 2023

What is CVE-2023-21441?

An insufficient verification of data authenticity vulnerability exists in Samsung's Routine. This flaw affects multiple Android versions, allowing a local attacker to exploit unused code, thereby gaining unauthorized access to protected files. Users are advised to update to the latest versions to mitigate this risk.

Affected Version(s)

Routine < 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12)

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.