First published: Tue Nov 07 2023(Updated: )
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Account | <14.5.00.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42547 is a vulnerability in Samsung Account that allows attackers to access arbitrary files using implicit intent for sensitive communication in startEmailValidationActivity.
The severity of CVE-2023-42547 is medium, with a CVSS score of 6.5.
CVE-2023-42547 allows attackers to exploit the vulnerable startEmailValidationActivity in Samsung Account to access arbitrary files by using implicit intents for sensitive communication.
Samsung Account versions prior to 14.5.00.7 are affected by CVE-2023-42547.
To fix CVE-2023-42547, users should update their Samsung Account to version 14.5.00.7 or later.