An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://security.samsungmobile.com/ | vendor advisory |
https://security.samsungmobile.com/securityUpdate.smsb | vendor advisory |