First published: Wed Oct 04 2023(Updated: )
Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.
Credit: mobile.security@samsung.com mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Samsung Assistant | <8.7.00.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-30736.
The severity of CVE-2023-30736 is medium with a CVSS score of 5.4.
CVE-2023-30736 allows improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1, allowing an attacker to execute JavaScript interface.
To trigger CVE-2023-30736, user interaction is required.
To fix CVE-2023-30736, update Samsung Assistant to version 8.7.00.1 or higher.