CVE-2023-21486: Medium severity samsung android vulnerability
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21486?
CVE-2023-21486 has a high severity rating due to the potential for physical attackers to access sensitive media data.
How do I fix CVE-2023-21486?
To address CVE-2023-21486, users should update their Samsung Android devices to the latest security patch provided in the SMR May-2023 Release 1.
Which versions of Samsung Android are affected by CVE-2023-21486?
CVE-2023-21486 affects Samsung Android versions 11.0 and 12.0 across multiple security maintenance releases.
What kind of data can be accessed due to CVE-2023-21486?
CVE-2023-21486 allows physical attackers to access some media data that is stored within the application's sandbox.
Is CVE-2023-21486 a remote vulnerability?
No, CVE-2023-21486 is classified as a physical access vulnerability, requiring the attacker to be physically present to exploit it.