CVE-2023-21446

MEDIUM

Samsung MyFiles <12.2.09/13.1.03.501/14.1.00.422 - Unauthenticated Data Access via Improper Input Validation

Title source: llm
STIX 2.1

Description

Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.

References (1)

Core 1

Scores

CVSS v3 6.2
EPSS 0.0006
EPSS Percentile 17.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
samsung/android 11.0 (37 CPE variants)
samsung/android 12.0 (13 CPE variants)
Published Feb 09, 2023
Tracked Since Feb 18, 2026