Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=06 | vendor advisory |