First published: Tue Nov 07 2023(Updated: )
Use of implicit intent for sensitive communication vulnerability in startSignIn in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Account | <14.5.00.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42550 is a vulnerability that allows attackers to access arbitrary files with Samsung Account privilege.
The severity of CVE-2023-42550 is medium with a CVSS score of 6.5.
CVE-2023-42550 allows attackers to access arbitrary files by exploiting the use of implicit intent for sensitive communication in the startSignIn function of Samsung Account prior to version 14.5.00.7.
There is no known fix available for CVE-2023-42550 at the moment.
The CWE ID for CVE-2023-42550 is 927.