Improper Access Control in Samsung Pay Mini Application
CVE-2021-25331
3.2LOW
What is CVE-2021-25331?
An improper access control vulnerability in the Samsung Pay mini application prior to version 4.0.14 enables unauthorized users to access sensitive balance information directly from the lockscreen under certain conditions. This vulnerability poses a risk of exposing private financial data, potentially allowing malicious actors to exploit the application without user consent. Users are urged to update to the latest version to mitigate this issue and enhance their security.
Affected Version(s)
Samsung Pay Mini < 4.0.14