CVE-2023-42547: Medium severity samsung account sdk vulnerability
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42547?
CVE-2023-42547 is a vulnerability in Samsung Account that allows attackers to access arbitrary files using implicit intent for sensitive communication in startEmailValidationActivity.
What is the severity of CVE-2023-42547?
The severity of CVE-2023-42547 is medium, with a CVSS score of 6.5.
How does CVE-2023-42547 work?
CVE-2023-42547 allows attackers to exploit the vulnerable startEmailValidationActivity in Samsung Account to access arbitrary files by using implicit intents for sensitive communication.
Which Samsung Account versions are affected by CVE-2023-42547?
Samsung Account versions prior to 14.5.00.7 are affected by CVE-2023-42547.
How can I fix CVE-2023-42547?
To fix CVE-2023-42547, users should update their Samsung Account to version 14.5.00.7 or later.