CVE-2023-21482: Samsung Camera
Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through Galaxy store before completion of Setup wizard.
Affected products
- Samsung Camera: before 11.1.02.18 (fixed in 11.1.02.18); before 12.1.03.8 (fixed in 12.1.03.8); before 13.1.04.4 (fixed in 13.1.04.4)
Published 2025-09-03. Last modified 2026-06-17.