CVE Published: 09/09/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: Samsung Mobile |
Vendor: Samsung Mobile |
Product: Samsung Pay Status : PUBLISHED
CVE-2022-36872 Description
Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
Metrics
CVSS Version: 3.1 |
Base Score: 5 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L