ZeroHour

CVE-2021-25381

CVSS 3.1
7.8 high
EPSS
<1%p12
Published
()
Modified
Description

Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

Vendors
samsung
Products
account
Weakness
CWE-285, CWE-276
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.