CVE-2021-25374: High severity samsung members vulnerability
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-25374?
CVE-2021-25374 has been classified with a severity that allows remote attackers to access sensitive user data.
How do I fix CVE-2021-25374?
To mitigate CVE-2021-25374, update the Samsung Members app to the latest version available from Samsung.
Which versions are affected by CVE-2021-25374?
CVE-2021-25374 affects Samsung Members versions 2.4.83.9 and earlier, as well as version 3.9.00.9 and later on Android 9.0.
What type of vulnerability is CVE-2021-25374?
CVE-2021-25374 is categorized as an improper authorization vulnerability.
Is my device vulnerable to CVE-2021-25374?
Devices running Samsung Members versions 2.4.83.9 or lower on Android O(8.1) and those on version 3.9.00.9 or higher on Android P(9.0) are vulnerable.