First published: Thu Feb 09 2023(Updated: )
Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Android | =11.0 | |
Samsung Android | =11.0-smr-apr-2021-r1 | |
Samsung Android | =11.0-smr-apr-2022-r1 | |
Samsung Android | =11.0-smr-apr-2023-r1 | |
Samsung Android | =11.0-smr-aug-2021-r1 | |
Samsung Android | =11.0-smr-aug-2022-r1 | |
Samsung Android | =11.0-smr-aug-2023-r1 | |
Samsung Android | =11.0-smr-dec-2020-r1 | |
Samsung Android | =11.0-smr-dec-2021-r1 | |
Samsung Android | =11.0-smr-dec-2022-r1 | |
Samsung Android | =11.0-smr-dec-2023-r1 | |
Samsung Android | =11.0-smr-feb-2021-r1 | |
Samsung Android | =11.0-smr-feb-2022-r1 | |
Samsung Android | =11.0-smr-feb-2023-r1 | |
Samsung Android | =11.0-smr-jan-2021-r1 | |
Samsung Android | =11.0-smr-jan-2022-r1 | |
Samsung Android | =11.0-smr-jul-2021-r1 | |
Samsung Android | =11.0-smr-jul-2022-r1 | |
Samsung Android | =11.0-smr-jul-2023-r1 | |
Samsung Android | =11.0-smr-jun-2021-r1 | |
Samsung Android | =11.0-smr-jun-2022-r1 | |
Samsung Android | =11.0-smr-jun-2023-r1 | |
Samsung Android | =11.0-smr-mar-2021-r1 | |
Samsung Android | =11.0-smr-mar-2022-r1 | |
Samsung Android | =11.0-smr-mar-2023-r1 | |
Samsung Android | =11.0-smr-may-2021-r1 | |
Samsung Android | =11.0-smr-may-2022-r1 | |
Samsung Android | =11.0-smr-may-2023-r1 | |
Samsung Android | =11.0-smr-nov-2021-r1 | |
Samsung Android | =11.0-smr-nov-2022-r1 | |
Samsung Android | =11.0-smr-nov-2023-r1 | |
Samsung Android | =11.0-smr-oct-2021-r1 | |
Samsung Android | =11.0-smr-oct-2022-r1 | |
Samsung Android | =11.0-smr-oct-2023-r1 | |
Samsung Android | =11.0-smr-sep-2021-r1 | |
Samsung Android | =11.0-smr-sep-2022-r1 | |
Samsung Android | =11.0-smr-sep-2023-r1 | |
Samsung Android | =12.0 | |
Samsung Android | =12.0-smr-apr-2022-r1 | |
Samsung Android | =12.0-smr-apr-2023-r1 | |
Samsung Android | =12.0-smr-aug-2022-r1 | |
Samsung Android | =12.0-smr-aug-2023-r1 | |
Samsung Android | =12.0-smr-dec-2021-r1 | |
Samsung Android | =12.0-smr-dec-2022-r1 | |
Samsung Android | =12.0-smr-dec-2023-r1 | |
Samsung Android | =12.0-smr-feb-2022-r1 | |
Samsung Android | =12.0-smr-feb-2023-r1 | |
Samsung Android | =12.0-smr-jan-2022-r1 | |
Samsung Android | =12.0-smr-jul-2022-r1 | |
Samsung Android | =12.0-smr-jul-2023-r1 | |
Samsung Android | =12.0-smr-jun-2022-r1 | |
Samsung Android | =12.0-smr-jun-2023-r1 | |
Samsung Android | =12.0-smr-mar-2022-r1 | |
Samsung Android | =12.0-smr-mar-2023-r1 | |
Samsung Android | =12.0-smr-may-2022-r1 | |
Samsung Android | =12.0-smr-may-2023-r1 | |
Samsung Android | =12.0-smr-nov-2021-r1 | |
Samsung Android | =12.0-smr-nov-2022-r1 | |
Samsung Android | =12.0-smr-nov-2023-r1 | |
Samsung Android | =12.0-smr-oct-2022-r1 | |
Samsung Android | =12.0-smr-oct-2023-r1 | |
Samsung Android | =12.0-smr-sep-2022-r1 | |
Samsung Android | =12.0-smr-sep-2023-r1 | |
Samsung Android | =13.0 | |
Samsung Android | =13.0-smr-apr-2023-r1 | |
Samsung Android | =13.0-smr-aug-2023-r1 | |
Samsung Android | =13.0-smr-dec-2022-r1 | |
Samsung Android | =13.0-smr-dec-2023-r1 | |
Samsung Android | =13.0-smr-feb-2023-r1 | |
Samsung Android | =13.0-smr-jul-2023-r1 | |
Samsung Android | =13.0-smr-jun-2023-r1 | |
Samsung Android | =13.0-smr-mar-2023-r1 | |
Samsung Android | =13.0-smr-may-2023-r1 | |
Samsung Android | =13.0-smr-nov-2022-r1 | |
Samsung Android | =13.0-smr-nov-2023-r1 | |
Samsung Android | =13.0-smr-oct-2022-r1 | |
Samsung Android | =13.0-smr-oct-2023-r1 | |
Samsung Android | =13.0-smr-sep-2023-r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21446 has a high severity level due to improper input validation allowing data access.
To fix CVE-2023-21446, users must update MyFiles to version 12.2.09 or later on affected Android devices.
CVE-2023-21446 affects Samsung Android versions prior to 12.2.09 for Android R, 13.1.03.501 for Android S, and 14.1.00.422 for Android T.
A local attacker can exploit CVE-2023-21446 to gain unauthorized access to MyFiles data.
No specific workaround for CVE-2023-21446 is mentioned; updating the affected software is recommended.