First published: Tue Nov 07 2023(Updated: )
PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Health | <6.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42539 is a vulnerability in Samsung Health prior to version 6.25 that allows local attackers to access data through a PendingIntent hijacking vulnerability in ChallengeNotificationManager.
CVE-2023-42539 has a severity rating of 5.5 (medium).
Samsung Health prior to version 6.25 is affected by CVE-2023-42539.
Local attackers can exploit CVE-2023-42539 by hijacking a PendingIntent in ChallengeNotificationManager to gain unauthorized access to data.
Yes, updating Samsung Health to version 6.25 or later will fix CVE-2023-42539.