
Cloud Vulnerability DB
A community-led vulnerabilities database
Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action (NVD, Samsung Mobile).
The vulnerability is classified as a moderate severity issue with CWE-20 (Improper Input Validation) designation. The flaw exists in the intent redirection mechanism of Samsung Health application, which could allow an attacker to execute actions with elevated privileges (NVD).
If exploited, this vulnerability allows attackers to execute privileged actions within the Samsung Health application context, potentially compromising the security boundaries of the application (Samsung Mobile).
The vulnerability requires local access to the device to exploit. It was discovered and reported by Sergey Toshin of Oversecured Inc (Samsung Mobile).
Samsung has addressed this vulnerability by releasing version 6.16 of the Samsung Health application. Users are advised to update their Samsung Health application to this version or later to protect against potential exploitation (Samsung Mobile).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."