Improper Exception Handling in Samsung Pay for NFC Transactions
CVE-2021-25525

2LOW

Key Information:

Vendor
Samsung
Vendor
CVE Published:
8 December 2021

Summary

A vulnerability in Samsung Pay for US users prior to version 4.0.65 allows attackers to exploit improper exception handling. This issue enables unauthorized NFC transactions without user consent, potentially exposing users to financial risks. Regular updates and patches are crucial for maintaining secure mobile payment systems.

Affected Version(s)

Samsung Pay - < 4.0.65

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.