CWE
284
Advisory Published
Updated

CVE-2022-36866

First published: Fri Sep 09 2022(Updated: )

Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.

Credit: mobile.security@samsung.com

Affected SoftwareAffected VersionHow to fix
Samsung Group Sharing<13.0.6.15
Android=12.0
Samsung Group Sharing<13.0.6.14
Android=11.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-36866?

    CVE-2022-36866 is rated as a high severity vulnerability due to improper access control allowing potential identification of devices.

  • How do I fix CVE-2022-36866?

    To fix CVE-2022-36866, update the Samsung Group Sharing application to version 13.0.6.15 or later.

  • What does CVE-2022-36866 exploit?

    CVE-2022-36866 exploits improper access control in the Broadcaster feature of the Samsung Group Sharing application.

  • Which versions of Samsung Group Sharing are affected by CVE-2022-36866?

    Versions of Samsung Group Sharing prior to 13.0.6.15 for Android S(12) and 13.0.6.14 for Android R(11) and below are affected.

  • Who is primarily impacted by CVE-2022-36866?

    Users of Samsung Group Sharing app on compatible Android devices prior to the specified versions are primarily impacted by CVE-2022-36866.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203