CVE-2019-20598

LOW

Android - Unauthenticated Information Disclosure via Bixby Lock Screen

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2019).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 2.4
EPSS 0.0013
EPSS Percentile 3.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-306
Status published
Products (2)
google/android 8.0
google/android 8.1
Published Mar 24, 2020
Tracked Since Feb 18, 2026