First published: Thu Mar 25 2021(Updated: )
Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Themes application without permission via hijacking the PendingIntent.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy Themes | <5.2.00.1215 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25353 has been classified as a high severity vulnerability due to its potential impact on user data privacy.
To fix CVE-2021-25353, update Samsung Galaxy Themes to version 5.2.00.1215 or later.
Users of Samsung Galaxy Themes versions prior to 5.2.00.1215 are affected by CVE-2021-25353.
CVE-2021-25353 allows local attackers to read and write private files within the Galaxy Themes application.
CVE-2021-25353 cannot be exploited remotely; it requires local access to the device.