Intent Hijacking Vulnerability in Samsung Pay
CVE-2022-36872

5MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
9 September 2022

Summary

The vulnerability in Samsung Pay arises from the SpayNotification component, which allows for pending Intent hijacking. This security flaw permits unauthorized access to files via implicit Intent, compromising user data and privacy. Users of Samsung Pay prior to specified versions are at risk and should seek updates to protect against potential exploitation.

Affected Version(s)

Samsung Pay < 5.0.63 for KR and 5.1.47 for Global

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.