First published: Fri Sep 09 2022(Updated: )
Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Group Sharing | <13.0.6.15 | |
Android | =12.0 | |
Samsung Group Sharing | <13.0.6.14 | |
Android | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36866 is rated as a high severity vulnerability due to improper access control allowing potential identification of devices.
To fix CVE-2022-36866, update the Samsung Group Sharing application to version 13.0.6.15 or later.
CVE-2022-36866 exploits improper access control in the Broadcaster feature of the Samsung Group Sharing application.
Versions of Samsung Group Sharing prior to 13.0.6.15 for Android S(12) and 13.0.6.14 for Android R(11) and below are affected.
Users of Samsung Group Sharing app on compatible Android devices prior to the specified versions are primarily impacted by CVE-2022-36866.