Sensitive Information Exposure in Samsung Contacts Application
CVE-2023-42556
5.5MEDIUM
Summary
The Contacts application by Samsung has a flaw due to improper usage of implicit intents, which can allow attackers to access sensitive user information. This vulnerability affects versions of Contacts prior to the SMR December 2023 Release 1, highlighting a critical area for users protecting their personal data.
Affected Version(s)
Samsung Mobile Devices SMR Dec-2023 Release in Android 11, 12, 13, 14
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved