CVE-2022-36873: Input Validation
Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36873?
CVE-2022-36873 has a medium severity level due to its potential to leak sensitive information, specifically the MAC address of connected Bluetooth devices.
How do I fix CVE-2022-36873?
To fix CVE-2022-36873, update the Galaxy Watch Plugin to version 2.2.11.22081151 or higher.
What devices are affected by CVE-2022-36873?
CVE-2022-36873 affects the Samsung Galaxy Watch Plugin versions prior to 2.2.11.22081151 on Android devices.
What does CVE-2022-36873 affect?
CVE-2022-36873 affects the broadcasting Intent mechanism in the GalaxyStoreBridgePageLinker of the Galaxy Watch Plugin.
Can CVE-2022-36873 lead to any unauthorized access?
CVE-2022-36873 can expose the MAC address of the Bluetooth device, potentially leading to privacy concerns but does not allow unauthorized access.