First published: Fri Feb 11 2022(Updated: )
Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Wear Os | <3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23995 is an unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to the February 2022 firmware update.
The severity of CVE-2022-23995 is rated as medium with a severity value of 3.3.
Untrusted applications can exploit CVE-2022-23995 to change bedtime mode without proper permission.
Samsung Wear OS versions up to and exclusive of 3.0 are affected by CVE-2022-23995.
To mitigate CVE-2022-23995, ensure you have installed the February 2022 firmware update for Wear OS 3.0 or later.