CVE-2023-30736

MEDIUM

Samsung Assistant < 8.7.00.1 - Unauthenticated JavaScript Interface Execution via PushMsgReceiver

Title source: llm
STIX 2.1

Description

Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.

References (1)

Core 1

Scores

CVSS v3 4.4
EPSS 0.0010
EPSS Percentile 26.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
samsung/samsung_assistant < 8.7.00.1
Published Oct 04, 2023
Tracked Since Feb 18, 2026