First published: Fri Apr 09 2021(Updated: )
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Members | <=2.4.83.9 | |
Android | =8.1 | |
Samsung Members | >=3.9.00.9 | |
Android | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25374 has been classified with a severity that allows remote attackers to access sensitive user data.
To mitigate CVE-2021-25374, update the Samsung Members app to the latest version available from Samsung.
CVE-2021-25374 affects Samsung Members versions 2.4.83.9 and earlier, as well as version 3.9.00.9 and later on Android 9.0.
CVE-2021-25374 is categorized as an improper authorization vulnerability.
Devices running Samsung Members versions 2.4.83.9 or lower on Android O(8.1) and those on version 3.9.00.9 or higher on Android P(9.0) are vulnerable.