Information Exposure Vulnerability in Samsung Members by Samsung
CVE-2021-25432
3.3LOW
What is CVE-2021-25432?
An information exposure vulnerability exists in Samsung Members prior to specific versions, where untrusted applications can gain unauthorized access to chat data. This flaw affects users with Android O (8.1) and below, as well as Android P (9.0) and above, exposing sensitive communications to potential exploitation. Users are advised to update their applications to mitigate this risk.
Affected Version(s)
Samsung Members - < 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved