cbcvebase.
CVE-2022-36873
published 2022-09-09

CVE-2022-36873: Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected…

medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.

Affected

2 ranges
VendorProductVersion rangeFixed in
samsunggalaxy_watch_plugin< 2.2.11.220811512.2.11.22081151
samsung_mobilecom.samsung.android.waterplugin>= unspecified < 2.2.11.220811512.2.11.22081151