CVE-2019-20579

LOW

Samsung Android N(7.x)-P(9.0) - Unauthenticated Location Information Sharing via Lock Screen

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to enable Location information sharing from the lock screen. The Samsung ID is SVE-2019-14462 (August 2019).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 2.4
EPSS 0.0014
EPSS Percentile 3.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-306
Status published
Products (7)
google/android 7.0
google/android 7.1.0
google/android 7.1.1
google/android 7.1.2
google/android 8.0
google/android 8.1
google/android 9.0
Published Mar 24, 2020
Tracked Since Feb 18, 2026