First published: Tue Mar 28 2023(Updated: )
This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of redirections. An attacker can force a redirection to a site that serves malicious content. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the current user.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy S21 | ||
Samsung Galaxy S21 Firmware | <4.5.40.5 | |
Samsung Galaxy S21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1230 is a vulnerability that allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to version 4.5.40.5.
The severity of CVE-2022-1230 is low with a severity value of 3.9.
CVE-2022-1230 affects Samsung Galaxy S21 prior to version 4.5.40.5.
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit CVE-2022-1230.
To fix CVE-2022-1230, users should update their Samsung Galaxy S21 devices to version 4.5.40.5 or later.