Information Exposure Vulnerability in Samsung Members by Samsung
CVE-2021-25432
3.3LOW
Summary
An information exposure vulnerability exists in Samsung Members prior to specific versions, where untrusted applications can gain unauthorized access to chat data. This flaw affects users with Android O (8.1) and below, as well as Android P (9.0) and above, exposing sensitive communications to potential exploitation. Users are advised to update their applications to mitigate this risk.
Affected Version(s)
Samsung Members - < 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved