CVE-2021-25373
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
Affected (4)
Products: Samsung: Customization Service
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2.02.1 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Version 8.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.03.0 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Version 9.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7.02.1 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Version 10.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.9.01.1 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Version 11.0 |
References (4)
Source: mobile.security@samsung.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.