CVE-2021-25352: High severity samsung bixby voice vulnerability
Published Mar 25, 2021
·Updated
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.
Affected Software
1 affected component
Samsung Bixby Voice<3.0.52.14
Event History
Mar 25, 2021
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-25352?
CVE-2021-25352 is a vulnerability that allows attackers to execute privileged actions in Bixby Voice by hijacking and modifying the intent when using PendingIntent with implicit intent.
2
What is the severity of CVE-2021-25352?
CVE-2021-25352 has a severity rating of 7.8 (High).
3
How does CVE-2021-25352 affect Bixby Voice?
CVE-2021-25352 affects Bixby Voice versions prior to 3.0.52.14.
4
How can attackers exploit CVE-2021-25352?
Attackers can exploit CVE-2021-25352 by hijacking and modifying the intent when using PendingIntent with implicit intent in Bixby Voice.
5
Is there a fix for CVE-2021-25352?
Yes, updating Bixby Voice to version 3.0.52.14 or newer is the recommended fix for CVE-2021-25352.