Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: SamsungMobile
Published: 2023-12-05T02:44:36.992Z
Updated: 2024-08-02T19:23:40.156Z
Reserved: 2023-09-11T23:55:08.357Z
Link: CVE-2023-42579
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-05T03:15:18.967
Modified: 2024-11-21T08:22:49.837
Link: CVE-2023-42579
Redhat
No data.