First published: Thu Mar 25 2021(Updated: )
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Notes | <4.2.00.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-25355.
The severity of CVE-2021-25355 is high with a CVSS score of 7.8.
Samsung Notes prior to version 4.2.00.22 is affected by CVE-2021-25355.
Local attackers can exploit CVE-2021-25355 by hijacking the PendingIntent and performing unauthorized actions without permission.
You can find more information about CVE-2021-25355 on the Samsung Mobile Security website.