VYPR
Unrated severityNVD Advisory· Published Oct 8, 2024· Updated Oct 8, 2024

CVE-2024-34671

CVE-2024-34671

Description

Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A translation feature in Samsung Internet prior to 26.0.3.1 uses implicit intents, letting local attackers obtain sensitive info with user interaction.

Vulnerability

In Samsung Internet versions prior to 26.0.3.1, the translation functionality leverages an implicit intent for sensitive communication. This design flaw allows a local attacker to intercept or read sensitive data being passed through the intent. User interaction is required to trigger the vulnerability. Affected versions: Samsung Internet prior to 26.0.3.1 [1].

Exploitation

An attacker must have local access to the device (e.g., a malicious app installed on the same device) and must be able to register an intent filter for the implicit intent used by the translation feature. When the user engages the translation functionality, the malicious app can intercept the intent and capture the sensitive information it contains [1].

Impact

Successful exploitation leads to disclosure of sensitive information to the local attacker. The exposed data could include user-provided text or other context transmitted via the translation feature. The compromise is limited to information disclosure and does not grant code execution or elevated privileges [1].

Mitigation

Samsung has addressed this vulnerability in Samsung Internet version 26.0.3.1. Users should update to this version or later. No workarounds are provided in the available references [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.