A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.
Storing a password in plaintext may result in a system compromise.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://security.samsungmobile.com/ | vendor advisory |
https://security.samsungmobile.com/securityUpdate.smsb | vendor advisory |