CVE-2023-42547

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 7, 2023
Updated: Nov 13, 2023
CWE ID 668

Summary

CVE-2023-42547 is a vulnerability affecting Samsung Account versions prior to 14.5.00.7. This issue stems from the use of implicit intent for sensitive communication in the startEmailValidationActivity function. An attacker can exploit this vulnerability to gain Samsung Account privileges and access arbitrary files on the affected system. This security flaw poses a significant risk to user data and privacy. It is essential that Samsung releases a patch to address this issue promptly. Users are advised to update their Samsung Account applications to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share