CVE-2023-30707: Input Validation
Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30707?
CVE-2023-30707 is considered a critical vulnerability as it allows local attackers to delete arbitrary files via improper input validation.
How do I fix CVE-2023-30707?
To remediate CVE-2023-30707, users should update their Samsung Keyboard application to the latest version available in the system updates.
Which versions of Samsung Android are affected by CVE-2023-30707?
CVE-2023-30707 affects Samsung Android versions 11.0 and specific security maintenance releases prior to September 2023.
Who can exploit CVE-2023-30707?
Local attackers with access to the device can exploit CVE-2023-30707 to delete arbitrary files using Samsung Keyboard privileges.
Are there any workarounds for CVE-2023-30707 before applying a fix?
Currently, there are no effective workarounds for CVE-2023-30707, and upgrading the application is the recommended course of action.