First published: Tue Mar 08 2022(Updated: )
An Improper access control vulnerability in StRetailModeReceiver in Wear OS 3.0 prior to Firmware update MAR-2022 Release allows untrusted applications to reset default app settings without a proper permission
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Wear Os | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24930 is an improper access control vulnerability in StRetailModeReceiver in Wear OS 3.0 prior to Firmware update MAR-2022 Release that allows untrusted applications to reset default app settings without proper permission.
CVE-2022-24930 affects Samsung Wear OS 3.0 prior to Firmware update MAR-2022 Release.
The severity of CVE-2022-24930 is medium, with a CVSS score of 3.3.
Untrusted applications can exploit CVE-2022-24930 to reset default app settings without the proper permission.
Yes, a firmware update released in MAR-2022 addresses the vulnerability and fixes CVE-2022-24930.