CVE-2024-20854

Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*

History

10 Oct 2025, 17:19

Type Values Removed Values Added
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04 - Vendor Advisory
CPE cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
First Time Google
Samsung
Google android
Samsung camera
CWE NVD-CWE-Other

21 Nov 2024, 08:53

Type Values Removed Values Added
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=04 -

02 Apr 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-02 03:15

Updated : 2025-10-10 17:19


NVD link : CVE-2024-20854

Mitre link : CVE-2024-20854

CVE.ORG link : CVE-2024-20854


JSON object : View

Products Affected

samsung

  • camera

google

  • android