The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NGoogle Android
OSGoogle12.013.0Samsung Quick Share
APPSamsung< 3.5.14.18< 3.5.16.20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2020-16010CRITICAL9.6⚠ KEVPL ✓same product
Heap buffer overflow w Google Chrome na Android — sandbox escape
CVE-2016-1019CRITICAL9.8⚠ KEVPL ✓same product
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
CVE-2026-78937CRITICAL9.6same product
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...
CVE-2026-79129CRITICAL9.6same product
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...
CVE-2026-79152CRITICAL9.8same product
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...