Implication of Implicit Intent in Bixby Voice by Samsung
CVE-2021-25352

5.5MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
25 March 2021

Summary

A vulnerability in Bixby Voice prior to version 3.0.52.14 allows attackers to exploit PendingIntent with implicit intent. This flaw can be leveraged to execute privileged actions by hijacking and modifying the intent, posing significant security risks to users. Timely updates and patches are essential to ensure protection against potential exploitation.

Affected Version(s)

Bixby Voice < 3.0.52.14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.