Improper Access Control in Samsung Members Affects Android Devices
CVE-2021-25439
3.3LOW
Summary
An improper access control vulnerability exists in Samsung Members, which affects devices running Android O (8.1) and below, as well as Android P (9.0) and above. This flaw allows untrusted applications to load arbitrary web pages within a webview, potentially exposing sensitive user data and enabling malicious behaviors. Timely software updates are essential to mitigate these risks.
Affected Version(s)
Samsung Members - < 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved