First published: Wed Dec 27 2017(Updated: )
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge of the local email address to obtain sensitive information via a crafted application that sends a crafted intent.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | <=5.1.1 | |
Samsung Galaxy S6 Edge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7889 is a vulnerability in the SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR.
CVE-2015-7889 has a severity level of 5.5 (medium).
The affected software includes Android version up to and including 5.1.1 and the Samsung Galaxy S6 Edge.
Remote attackers with knowledge of the local email address can exploit CVE-2015-7889 to obtain sensitive information.
Yes, you can find more information about CVE-2015-7889 at the following references: [1](http://packetstormsecurity.com/files/134105/Samsung-SecEmailComposer-QUICK_REPLY_BACKGROUND-Permission-Weakness.html), [2](http://www.securityfocus.com/bid/77339), [3](https://bugs.chromium.org/p/project-zero/issues/detail.id=490&redir=1)