First published: Tue Dec 03 2024(Updated: )
Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
SmartThings | <1.8.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49416 is considered a medium severity vulnerability due to its potential for local attackers to access sensitive information.
To fix CVE-2024-49416, update Samsung SmartThings to version 1.8.21 or later.
All versions of Samsung SmartThings prior to 1.8.21 are affected by CVE-2024-49416.
CVE-2024-49416 allows local attackers to access sensitive information transmitted through implicit intents.
Mitigating risks for CVE-2024-49416 involves ensuring that your SmartThings application is updated to the latest secure version.