CVE-2022-24923

MEDIUM

Samsung SearchWidget < 2.3.00.6 - Improper Access Control

Title source: llm
STIX 2.1

Description

Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

References (1)

Core 1
Core References

Scores

CVSS v3 4.0
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-284
Status published
Products (1)
samsung/searchwidget < 2.3.00.6
Published Feb 11, 2022
Tracked Since Feb 18, 2026