Information disclosure in Google Android - CVE-2018-21059

 

Information disclosure in Google Android - CVE-2018-21059

Published: April 8, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34487
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-21059
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard content visibility in the locked state via the emergency contact picker. The Samsung ID is SVE-2018-11806 (September 2018).


Affected software

Google Android

How to mitigate CVE-2018-21059

Install update from vendor's website.


External References

Related Security Bulletins