First published: Mon Dec 31 2012(Updated: )
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly implement Location APIs, which allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Dive | ||
Samsung Galaxy Note 2 firmware | ||
Samsung Galaxy S | ||
Samsung Galaxy S2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-6334 is considered to be a medium risk due to potential unauthorized location manipulation.
To mitigate CVE-2012-6334, users should update their Samsung devices to the latest firmware version provided by Samsung.
CVE-2012-6334 affects Samsung Galaxy devices that utilize the SamsungDive feature.
CVE-2012-6334 enables attackers to spoof GPS location data on affected Samsung devices.
No, CVE-2012-6334 is specifically related to the SamsungDive subsystem and does not affect all Samsung devices.