First published: Fri Oct 07 2022(Updated: )
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
SmartThings | <1.7.85.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39864 is considered a medium severity vulnerability due to improper access control allowing unauthorized information access.
To fix CVE-2022-39864, update the SmartThings app to version 1.7.89.25 or later.
CVE-2022-39864 is an improper access control vulnerability affecting the WifiSetupLaunchHelper in SmartThings.
Users of Samsung SmartThings app versions prior to 1.7.89.25 on Android devices are affected by CVE-2022-39864.
Attackers exploiting CVE-2022-39864 can access sensitive information through implicit intents.