First published: Tue Jun 07 2022(Updated: )
PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
SmartThings | <1.7.85.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30747 is classified as a medium severity vulnerability.
To mitigate CVE-2022-30747, update the Smart Things app to version 1.7.85.25 or later.
CVE-2022-30747 allows local attackers to gain unauthorized access to files on devices running vulnerable versions of the Smart Things app.
CVE-2022-30747 affects all versions of Smart Things prior to 1.7.85.25.
Any user running an affected version of the Smart Things app on their Android device is vulnerable to CVE-2022-30747.