Improper Access Control in Samsung Notification Service
CVE-2024-20806

6.2MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
4 January 2024

Summary

An improper access control vulnerability exists in Samsung's Notification service, which may allow a local attacker to access sensitive notification data. This vulnerability is present in versions of the Notification service prior to the SMR January 2024 Release 1, potentially compromising user privacy and data integrity.

Affected Version(s)

Samsung Mobile Devices SMR Jan-2024 Release in Android 11, 12, 13, 14

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.