Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published: 2023-12-05T02:44:36.992Z

Updated: 2024-08-02T19:23:40.156Z

Reserved: 2023-09-11T23:55:08.357Z

Link: CVE-2023-42579

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-05T03:15:18.967

Modified: 2023-12-12T21:22:00.157

Link: CVE-2023-42579

cve-icon Redhat

No data.