CVE Published: 09/04/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: Samsung Mobile |
Vendor: Samsung Mobile |
Product: Samsung Account Status : PUBLISHED
CVE-2021-25381 Description
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
Metrics
CVSS Version: 3.1 |
Base Score: 5.5 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N