CVE-2024-20840

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:voice_recorder:*:*:*:*:*:*:*:*
OR cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:voice_recorder:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*

History

14 Feb 2025, 17:27

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:a:samsung:voice_recorder:*:*:*:*:*:*:*:*
First Time Google
Google android
Samsung voice Recorder
Samsung
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 - Vendor Advisory

21 Nov 2024, 08:53

Type Values Removed Values Added
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 -

05 Mar 2024, 13:41

Type Values Removed Values Added
Summary
  • (es) El control de acceso inadecuado en Samsung Voice Recorder anterior a las versiones 21.5.16.01 en Android 12 y Android 13, 21.4.51.02 en Android 14 permite a atacantes físicos que usan un teclado de hardware usar VoiceRecorder en la pantalla de bloqueo.

05 Mar 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-05 05:15

Updated : 2025-02-14 17:27


NVD link : CVE-2024-20840

Mitre link : CVE-2024-20840

CVE.ORG link : CVE-2024-20840


JSON object : View

Products Affected

google

  • android

samsung

  • voice_recorder