Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2021&month=5 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Samsung Mobile
Published: 2021-06-11T14:45:23
Updated: 2021-06-11T14:45:23
Reserved: 2021-01-19T00:00:00
Link: CVE-2021-25403
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-06-11T15:15:09.653
Modified: 2022-07-30T12:58:06.853
Link: CVE-2021-25403
JSON object: View
Redhat Information
No data.
CWE