Samsung SLocation Improper Access Control Vulnerability Allowing Location Data Access
Vulnerability
A vulnerability exists in the SLocation application on Samsung devices running Android 11, 12, and 13, prior to the April 2023 Security Maintenance Release. This improper access control vulnerability allows local attackers to retrieve device location information by using specific actions related to network location and geofencing. The issue arises from inadequate authorization mechanisms that fail to restrict access to sensitive location data.
Impact
Exploitation of this vulnerability could lead to unauthorized access to the device's location information, potentially allowing attackers to track the user's movements or determine their whereabouts.
Remediation
Users can update their devices to the April 2023 Security Maintenance Release to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
