ZeroHour

CVE-2022-36870

CVSS 3.1
6.5 medium
EPSS
<1%p7
Published
()
Modified
Description

Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

Vendors
samsung
Products
samsung pay, samsung pay kr
Weakness
CWE-285
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.