QID 610557

Date Published: 2024-04-09

QID 610557: Google Android April 2024 Security Patch Missing for Samsung

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets.

Following security issues were discovered:
CVE-2023-28578,CVE-2023-6143, CVE-2023-6241, CVE-2024-20020, CVE-2024-20005, CVE-2024-20026, CVE-2024-20028, CVE-2024-20025, CVE-2024-20027, CVE-2024-20023, CVE-2024-20024, CVE-2023-33066, CVE-2023-43550, CVE-2023-33042, CVE-2023-43548, CVE-2023-43539, CVE-2023-43549, CVE-2023-43552, CVE-2023-43553, CVE-2024-23710, CVE-2024-23713, CVE-2024-0022, CVE-2024-23712, CVE-2024-23704, CVE-2023-21267, CVE-2024-0026, CVE-2024-0027,CVE-2024-20842,CVE-2024-20843,CVE-2024-20844,CVE-2024-20845,CVE-2024-20846,CVE-2024-20848,CVE-2024-20849,CVE-2024-20847

Affected Products :
Galaxy Z Fold2, Galaxy Z Fold2 5G, Galaxy Z Fold3 5G, Galaxy Z Fold4, Galaxy Z Fold5, Galaxy Z Flip3 5G, Galaxy Z Flip4, Galaxy Z Flip5, W23, W23 flip Galaxy S20, Galaxy S20 5G, Galaxy S20+, Galaxy S20+ 5G, Galaxy S20 Ultra, Galaxy S20 Ultra 5G, Galaxy S20 FE, Galaxy S20 FE 5G, Galaxy S21 5G, Galaxy S21+ 5G, Galaxy S21 Ultra 5G, Galaxy S21 FE 5G, Galaxy S22, Galaxy S22+, Galaxy S22 Ultra, Galaxy S23, Galaxy S23+, Galaxy S23 Ultra Galaxy Note20, Galaxy Note20 5G, Galaxy Note20 Ultra, Galaxy Note20 Ultra 5G Enterprise Models: Galaxy A52, Galaxy A52 5G, Galaxy A52s 5G, Galaxy A53 5G, Galaxy A54 5G, Galaxy Xcover5, Galaxy Xcover6 Pro

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Samsung Security advisory SMR-April-2024 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SMR-April-2024 Android URL Logo security.samsungmobile.com/securityUpdate.smsb