Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=7 | vendor advisory |