Information Exposure Vulnerability in Samsung Members by Samsung
CVE-2021-25432

3.3LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
8 July 2021

Summary

An information exposure vulnerability exists in Samsung Members prior to specific versions, where untrusted applications can gain unauthorized access to chat data. This flaw affects users with Android O (8.1) and below, as well as Android P (9.0) and above, exposing sensitive communications to potential exploitation. Users are advised to update their applications to mitigate this risk.

Affected Version(s)

Samsung Members - < 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.