CVE-2024-20854

Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*

History

10 Oct 2025, 17:19

Type Values Removed Values Added
First Time Google android
Samsung
Google
Samsung camera
CPE cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04 - Vendor Advisory
CWE NVD-CWE-Other

Information

Published : 2024-04-02 03:15

Updated : 2025-10-10 17:19


NVD link : CVE-2024-20854

Mitre link : CVE-2024-20854

CVE.ORG link : CVE-2024-20854


JSON object : View

Products Affected

google

  • android

samsung

  • camera