Vulnerability Description
Samsung S9+, S10, and XCover 4 P(9.0) devices can become temporarily inoperable because of an unprotected intent in the ContainerAgent application. For example, the victim becomes stuck in a launcher with their Secure Folder locked. NOTE: the researcher mentions "the Samsung Security Team considered this issue as no/little security impact.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | S9\+ Firmware | - |
| Samsung | S9\+ | - |
| Samsung | S10 Firmware | - |
| Samsung | S10 | - |
| Samsung | Xcover 4 Firmware | - |
| Samsung | Xcover 4 | - |
Related Weaknesses (CWE)
References
- https://github.com/fs0c131y/SamsungLockerExploitThird Party Advisory
- https://github.com/fs0c131y/SamsungLockerExploitThird Party Advisory
FAQ
What is CVE-2019-12087?
CVE-2019-12087 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Samsung S9+, S10, and XCover 4 P(9.0) devices can become temporarily inoperable because of an unprotected intent in the ContainerAgent application. For example, the victim becomes stuck in a launcher ...
How severe is CVE-2019-12087?
CVE-2019-12087 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12087?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung S9\+ Firmware, Samsung S9\+, Samsung S10 Firmware, Samsung S10, Samsung Xcover 4 Firmware.