Improper Access Control in Samsung Members Affects Android Devices
CVE-2021-25439

3.3LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
8 July 2021

Summary

An improper access control vulnerability exists in Samsung Members, which affects devices running Android O (8.1) and below, as well as Android P (9.0) and above. This flaw allows untrusted applications to load arbitrary web pages within a webview, potentially exposing sensitive user data and enabling malicious behaviors. Timely software updates are essential to mitigate these risks.

Affected Version(s)

Samsung Members - < 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.