First published: Tue Nov 07 2023(Updated: )
Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Account | <14.5.00.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42551 is a vulnerability that allows attackers to access arbitrary files with Samsung Account privilege.
CVE-2023-42551 has a severity level of medium (6.5).
CVE-2023-42551 occurs due to the use of an implicit intent for sensitive communication in startTncActivity in Samsung Account.
Samsung Account versions prior to 14.5.00.7 are affected by CVE-2023-42551.
To fix CVE-2023-42551, update Samsung Account to version 14.5.00.7 or higher.