First published: Tue Apr 11 2017(Updated: )
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy S6 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7893 has been assigned a medium severity rating due to its potential for remote code execution via JavaScript injection.
To fix CVE-2015-7893, ensure that your Samsung Galaxy S6 firmware is updated to the latest version provided by Samsung.
CVE-2015-7893 allows attackers to execute arbitrary JavaScript within the SecEmailUI component of the Samsung Galaxy S6.
CVE-2015-7893 primarily affects the Samsung Galaxy S6 and may involve other versions with the same email client feature.
Yes, CVE-2015-7893 typically requires user interaction, as the attacker must trick the user into opening a malicious email.