SB2022101442 - Incorrect authorization in Samsung Internet



SB2022101442 - Incorrect authorization in Samsung Internet

Published: October 14, 2022

Security Bulletin ID SB2022101442
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Incorrect authorization (CVE-ID: CVE-2022-39873)

The vulnerability allows a local attacker to bypass authorization checks.

The vulnerability exists due to unprotected receiver in AtBroadcastReceiver. An attacker with physical access can add bookmarks in secret mode without user authentication.


Remediation

Install update from vendor's website.