First published: Fri Apr 09 2021(Updated: )
Improper handling of exceptional conditions in Bixby prior to version 3.0.53.02 allows attacker to execute the actions registered by the user.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Bixby | <3.0.53.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25380 is classified as a high-severity vulnerability due to its potential to allow unauthorized actions by an attacker.
To fix CVE-2021-25380, update Samsung Bixby to version 3.0.53.02 or later.
CVE-2021-25380 is caused by improper handling of exceptional conditions in Bixby, allowing execution of user-registered actions.
CVE-2021-25380 affects users of Samsung Bixby versions prior to 3.0.53.02.
Yes, an attacker can exploit CVE-2021-25380 remotely if the vulnerable version of Bixby is installed.