CVE-2024-20840

MEDIUM

Samsung Voice Recorder <21.5.16.01-21.4.51.02 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen.

References (1)

Core 1

Scores

CVSS v3 5.7
EPSS 0.0004
EPSS Percentile 11.5%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
samsung/voice_recorder < 21.5.16.01
Published Mar 05, 2024
Tracked Since Feb 18, 2026