CVE-2021-25432
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD
Description
Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data.
Affected (2)
Products: Samsung: Samsung Members
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.85.11 |
| Running on/with | Platform Versions |
|---|---|
Google Android | Up to 8.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.9.10.11 |
| Running on/with | Platform Versions |
|---|---|
Google Android | From 9.0 |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References (2)
Source: mobile.security@samsung.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.