Intent Hijacking Vulnerability in Samsung Pay
CVE-2022-36872
5MEDIUM
Summary
The vulnerability in Samsung Pay arises from the SpayNotification component, which allows for pending Intent hijacking. This security flaw permits unauthorized access to files via implicit Intent, compromising user data and privacy. Users of Samsung Pay prior to specified versions are at risk and should seek updates to protect against potential exploitation.
Affected Version(s)
Samsung Pay < 5.0.63 for KR and 5.1.47 for Global
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved