Executive brief
Samsung KNOX, a security platform for mobile devices, contains a flaw in how it manages clipboard data. This vulnerability allows a malicious application installed on the device to access and read sensitive information copied to the clipboard within the secure KNOX container. This could lead to the theft of passwords, personal messages, or corporate data that a user has copied while using protected apps.
Technical details
An information disclosure vulnerability exists in the ClipboardDataMgr component of Samsung KNOX versions 1.0.0 and 2.3.0. The component fails to adequately validate the identity or authorization of the calling process when requests are made to access clipboard content. A local attacker can exploit this by tricking a user into installing a crafted application that programmatically queries the ClipboardDataMgr. Successful exploitation allows the attacker to bypass the isolation boundaries of the KNOX container to retrieve sensitive data stored in the clipboard.
Affected products
- Samsung KNOX 1.0.0, 2.3.0
Timeline
- 2016-04-15: disclosed: Initial public disclosure via Packet Storm Security
- 2017-01-27: advisory: NVD publication date