Improper Authorization Vulnerability in Samsung Assistant
CVE-2023-30736
4.4MEDIUM
Summary
An improper authorization vulnerability in the PushMsgReceiver component of Samsung Assistant allows an attacker to execute unauthorized JavaScript interfaces. User interaction is necessary to exploit this flaw, making it crucial for users to be cautious about the applications they engage with and the permissions they grant. Updates to versions beyond 8.7.00.1 are recommended to mitigate this risk. For further details, visit Samsung's security advisories.
Affected Version(s)
Samsung Assistant 8.7.00.1
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved