CVE-2021-25403: Infoleak
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25403?
CVE-2021-25403 is an intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above.
How severe is CVE-2021-25403?
CVE-2021-25403 has a severity rating of 3.3, which is considered low.
What is the affected software?
The affected software includes Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above.
How can an attacker exploit CVE-2021-25403?
An attacker can exploit CVE-2021-25403 to access contacts and file provider using the SettingWebView component.
Is Google Android vulnerable to CVE-2021-25403?
No, Google Android is not vulnerable to CVE-2021-25403.