PendingIntent Vulnerability in Samsung Reminder App
CVE-2022-22285

4.4MEDIUM

Key Information:

Vendor
Samsung
Status
Vendor
CVE Published:
10 January 2022

Summary

A vulnerability exists in the Samsung Reminder application where the PendingIntent can be misused to execute unauthorized actions. This flaw affects versions prior to 12.2.05.0 in Samsung Reminder for Android R (11.0) and prior to 12.3.02.1000 in Android S (12.0). By exploiting this vulnerability, an attacker can hijack the intent to carry out privileged actions, potentially leading to a breach of user privacy and security.

Affected Version(s)

Reminder - < 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0)

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.