CVE-2021-25333: Infoleak
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-25333?
CVE-2021-25333 is considered a medium severity vulnerability due to potential unauthorized access to sensitive balance information.
How do I fix CVE-2021-25333?
To fix CVE-2021-25333, update your Samsung Pay mini application to version 4.0.14 or later as this version addresses the access control issue.
What is the impact of CVE-2021-25333?
The impact of CVE-2021-25333 allows unauthorized users to access balance information through a specific QR code while the device is locked.
Which versions of Samsung Pay mini are affected by CVE-2021-25333?
Versions of Samsung Pay mini prior to v4.0.14 are affected by CVE-2021-25333.
Is user action required for CVE-2021-25333?
Yes, users need to manually update their Samsung Pay mini application to resolve the vulnerability associated with CVE-2021-25333.