Sensitive Information Exposure in Quick Share Agent by Samsung
CVE-2023-21462
3.3LOW
Summary
A vulnerability in Samsung's Quick Share Agent allows local attackers to exploit sensitive information exposure. Specifically, the flaw permits unauthorized access to the device's MAC address without the necessary permissions. This issue affects users on Android 12 and Android 13 running versions prior to 3.5.14.18 and 3.5.16.20, respectively. To mitigate this risk, it is advisable for users to update their applications to the latest available versions, ensuring enhanced security measures against potential data leaks.
Affected Version(s)
Quick Share Agent < 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved