First published: Thu Mar 25 2021(Updated: )
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Bixby Voice | <3.0.52.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25352 is a vulnerability that allows attackers to execute privileged actions in Bixby Voice by hijacking and modifying the intent when using PendingIntent with implicit intent.
CVE-2021-25352 has a severity rating of 7.8 (High).
CVE-2021-25352 affects Bixby Voice versions prior to 3.0.52.14.
Attackers can exploit CVE-2021-25352 by hijacking and modifying the intent when using PendingIntent with implicit intent in Bixby Voice.
Yes, updating Bixby Voice to version 3.0.52.14 or newer is the recommended fix for CVE-2021-25352.