First published: Thu Mar 04 2021(Updated: )
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Pay mini | <4.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25333 is considered a medium severity vulnerability due to potential unauthorized access to sensitive balance information.
To fix CVE-2021-25333, update your Samsung Pay mini application to version 4.0.14 or later as this version addresses the access control issue.
The impact of CVE-2021-25333 allows unauthorized users to access balance information through a specific QR code while the device is locked.
Versions of Samsung Pay mini prior to v4.0.14 are affected by CVE-2021-25333.
Yes, users need to manually update their Samsung Pay mini application to resolve the vulnerability associated with CVE-2021-25333.