Sensitive Information Exposure in Samsung Contacts Application
CVE-2023-42556

5.5MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
5 December 2023

Summary

The Contacts application by Samsung has a flaw due to improper usage of implicit intents, which can allow attackers to access sensitive user information. This vulnerability affects versions of Contacts prior to the SMR December 2023 Release 1, highlighting a critical area for users protecting their personal data.

Affected Version(s)

Samsung Mobile Devices SMR Dec-2023 Release in Android 11, 12, 13, 14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.