First published: Tue Nov 07 2023(Updated: )
Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Account | <14.5.00.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-42548.
The title of this vulnerability is 'Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account'.
The description of this vulnerability is 'Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.'
Samsung Account versions prior to 14.5.00.7 are affected by this vulnerability.
The severity of this vulnerability is medium with a CVSS score of 6.5.
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-927.
To fix this vulnerability, update your Samsung Account to version 14.5.00.7 or later.