SB2024040255 - Improper access control in Samsung Gallery
Published: April 2, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2024-20827)
The vulnerability allows an attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions. An attacker with physical access to device can bypass implemented security restrictions and access the picture using physical keyboard on the lockscreen.
Remediation
Install update from vendor's website.