CVE-2023-21445 MEDIUM

CVE-2023-21445

Vendor Samsung Mobile
Product The patch adds proper access control to use explicit intent.
Weakness CWE-284
Published February 9, 2023
Last update March 24, 2025

CVSS base score

5.5/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.

Key dates

02Disclosure timeline

February 9, 2023 CVE published
March 24, 2025 Record updated