First published: Thu Jul 08 2021(Updated: )
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Members | <2.4.85.11 | |
Android | <=8.1 | |
Samsung Members | =3.9.10.11 | |
Android | >=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25438 has been classified as a medium severity vulnerability.
To fix CVE-2021-25438, update Samsung Members to version 2.4.85.11 or later for Android O(8.1) and to 3.9.10.11 or later for Android P(9.0) and above.
CVE-2021-25438 affects users of Samsung Members versions prior to 2.4.85.11 and 3.9.10.11 on the specified Android versions.
Exploitation of CVE-2021-25438 could allow untrusted applications to cause local file inclusion in the webview context.
You can check if your device is vulnerable to CVE-2021-25438 by verifying the version of Samsung Members installed on your device.