PT-2020-8704 · Samsung · Samsung Mobile Devices
Published
2020-04-08
·
Updated
2020-04-09
·
CVE-2018-21060
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung mobile devices with N(7.x) software
Samsung mobile devices with O(8.x) software
Description
An issue was discovered where there is a Keyboard learned words leak in the locked state via the emergency contact picker.
Recommendations
For Samsung mobile devices with N(7.x) software, update to a version that addresses the issue.
For Samsung mobile devices with O(8.x) software, update to a version that addresses the issue.
As a temporary workaround, consider restricting access to the emergency contact picker in the locked state to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Mobile Devices