CVE-2023-42541: Samsung Push Service

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.

Affected products

  • Samsung Push Service: before 3.4.10 (fixed in 3.4.10)

Published 2023-11-07. Last modified 2026-06-17.