Samsung Mobile Improper Access Control Vulnerability in MiscPolicy

Vulnerability

An improper access control vulnerability has been identified in the 'retrieveExternalProxy' function within the MiscPolicy component of Samsung Mobile devices. This vulnerability, present in versions Q(10), R(11), and S(12) prior to the November 2022 Security Maintenance Release, allows local attackers to access proxy information. The issue arises from inadequate access controls, which the latest update addresses by implementing proper permissions to prevent unauthorized access.

Impact

Exploitation of this vulnerability could lead to unauthorized access to proxy information, potentially allowing for interception or manipulation of network traffic.

Remediation

Users can apply the November 2022 Security Maintenance Release to address this vulnerability. This update is part of the monthly security update process and includes patches from both Google and Samsung.

Added: Sep 4, 2025, 11:46 AM
Updated: Sep 4, 2025, 5:01 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.