First published: Tue Mar 05 2024(Updated: )
Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Voice Recorder | <21.5.16.01<21.4.51.02 | |
All of | ||
Samsung Voice Recorder | <21.5.16.01 | |
Any of | ||
Android | =12.0 | |
Android | =13.0 | |
All of | ||
Samsung Voice Recorder | <21.4.51.02 | |
Android | =14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20840 is rated as a high severity vulnerability due to the potential for unauthorized access to the Voice Recorder on locked devices.
To fix CVE-2024-20840, update the Samsung Voice Recorder application to version 21.5.16.01 or later for Android 12 and 13, or version 21.4.51.02 or later for Android 14.
CVE-2024-20840 affects users of Samsung Voice Recorder prior to specified versions on Android 12, 13, and 14.
CVE-2024-20840 can allow physical attackers to access the Voice Recorder app while the device is locked, potentially compromising user privacy.
CVE-2024-20840 was disclosed in March 2024, addressing an important security concern for Samsung Voice Recorder users.