Implication of Implicit Intent in Bixby Voice by Samsung
CVE-2021-25352
5.5MEDIUM
Summary
A vulnerability in Bixby Voice prior to version 3.0.52.14 allows attackers to exploit PendingIntent with implicit intent. This flaw can be leveraged to execute privileged actions by hijacking and modifying the intent, posing significant security risks to users. Timely updates and patches are essential to ensure protection against potential exploitation.
Affected Version(s)
Bixby Voice < 3.0.52.14
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved