Severity
5.5MEDIUM
EPSS
0.2%
top 59.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11
Latest updateFeb 12

Description

Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6

Affected Packages2 packages

NVDsamsung/camera< 11.1.02.16+2
CVEListV5samsung_mobile/samsung_camera-11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9)

🔴Vulnerability Details

2
GHSA
GHSA-m2w8-37g8-4987: Improper access control vulnerability in Camera prior to versions 112022-02-12
CVEList
CVE-2022-23998: Improper access control vulnerability in Camera prior to versions 112022-02-11
CVE-2022-23998 (MEDIUM CVSS 5.5) | Improper access control vulnerabili | cvebase.io