Intent Redirection Vulnerability in Samsung Account for Android Devices
CVE-2021-25403

3.3LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
11 June 2021

Summary

An intent redirection vulnerability in Samsung Account allows attackers to exploit the SettingWebView component, potentially gaining unauthorized access to sensitive data such as contacts and file providers. This vulnerability affects users on specific versions of Android, highlighting the importance of keeping software updated to mitigate the risk of exploitation.

Affected Version(s)

Samsung Account < 10.8.0.4 in Android P(9.0) below, and 12.2.0.9 in Android Q(10.0) above

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.