PT-2020-8704 · Samsung · Samsung Mobile Devices

Published

2020-04-08

·

Updated

2020-04-09

·

CVE-2018-21060

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung mobile devices with N(7.x) software Samsung mobile devices with O(8.x) software
Description An issue was discovered where there is a Keyboard learned words leak in the locked state via the emergency contact picker.
Recommendations For Samsung mobile devices with N(7.x) software, update to a version that addresses the issue. For Samsung mobile devices with O(8.x) software, update to a version that addresses the issue. As a temporary workaround, consider restricting access to the emergency contact picker in the locked state to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-21060

Affected Products

Samsung Mobile Devices