First published: Mon Apr 11 2022(Updated: )
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Accessibility | <12.5.3.2 | |
Android | =11.0 | |
Samsung Accessibility | <13.0.1.1 | |
Android | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27837 is classified as a high severity vulnerability due to potential unauthorized file access with system privileges.
To fix CVE-2022-27837, update your Samsung Accessibility application to version 12.5.3.2 or higher.
CVE-2022-27837 affects Samsung Accessibility applications prior to version 12.5.3.2 on Android R (11.0) and Android S (12.0) up to version 13.0.1.1.
CVE-2022-27837 allows attackers to exploit the PendingIntent feature to gain unauthorized access to files with system privileges.
Yes, CVE-2022-27837 specifically affects the Samsung Accessibility application on designated Android versions.