SB2022101442 - Incorrect authorization in Samsung Internet
Published: October 14, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect authorization (CVE-ID: CVE-2022-39873)
The vulnerability allows a local attacker to bypass authorization checks.
The vulnerability exists due to unprotected receiver in AtBroadcastReceiver. An attacker with physical access can add bookmarks in secret mode without user authentication.
Remediation
Install update from vendor's website.