First published: Tue Nov 07 2023(Updated: )
Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Account | <14.5.00.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-42546.
The severity of CVE-2023-42546 is medium (6.5).
The affected software for CVE-2023-42546 is Samsung Account prior to version 14.5.00.7.
Attackers can exploit CVE-2023-42546 by accessing arbitrary files with Samsung Account privilege using a use of implicit intent for sensitive communication in startAgreeToDisclaimerActivity.
You can find more information about CVE-2023-42546 at this [link](https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11).