CVE-2023-21458
Description
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An improper privilege management vulnerability in Samsung System UI allows any app to disable Do Not Disturb via an unprotected intent.
Vulnerability
An improper privilege management vulnerability exists in PhoneStatusBarPolicy within System UI on Samsung devices running firmware prior to SMR Mar-2023 Release 1. The component exposes an unprotected intent that can be used to toggle the Do not disturb (DND) setting without requiring any special permissions [1].
Exploitation
An attacker only needs to install a malicious application on the target device. No additional permissions, user interaction, or network access is required. The app sends an unprotected intent to the PhoneStatusBarPolicy component, which silently accepts the command and disables DND [1].
Impact
By turning off Do not disturb, the attacker can cause the device to ring, vibrate, or play notification sounds at any time, potentially disrupting the user in meetings, during sleep, or in other quiet environments. This reduces user control over their device ringer settings and can lead to embarrassment or privacy leaks if audible alerts occur in sensitive contexts. The attacker does not gain access to user data or other system capabilities [1].
Mitigation
The vulnerability is fixed in SMR Mar-2023 Release 1, released in March 2023. Users should update their Samsung device firmware via the Samsung Security Update process. There is no known workaround for unpatched devices; the only mitigation is to apply the security update [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: < SMR Mar-2023 Release 1
- Range: Android 11, 12, 13
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.