Information Exposure Vulnerability in Samsung Members by Samsung
CVE-2021-25432

3.3LOW

Key Information:

Vendor

Samsung

Vendor
CVE Published:
8 July 2021

What is CVE-2021-25432?

An information exposure vulnerability exists in Samsung Members prior to specific versions, where untrusted applications can gain unauthorized access to chat data. This flaw affects users with Android O (8.1) and below, as well as Android P (9.0) and above, exposing sensitive communications to potential exploitation. Users are advised to update their applications to mitigate this risk.

Affected Version(s)

Samsung Members - < 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.