First published: Fri Aug 05 2022(Updated: )
PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Charm Firmware | <1.2.3 | |
Samsung Charm Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36829 is classified as a high severity vulnerability.
To fix CVE-2022-36829, update the Samsung Charm app to version 1.2.3 or later.
CVE-2022-36829 allows local attackers to exploit PendingIntent hijacking to access files without permission.
Samsung Charm versions prior to 1.2.3 are affected by CVE-2022-36829.
Yes, the Samsung Charm firmware prior to version 1.2.3 is vulnerable to CVE-2022-36829.