CVE-2023-21450: Samsung One Hand Operation +

Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner's widget without authorization via gesture setting.

Affected products

  • Samsung One Hand Operation +: before 6.1.21 (fixed in 6.1.21)

Published 2023-02-09. Last modified 2026-06-17.