First published: Thu Jul 08 2021(Updated: )
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Members | <2.4.85.11 | |
Google Android | <=8.1 | |
Samsung Members | =3.9.10.11 | |
Google Android | >=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25439 is rated as a high severity vulnerability due to its potential to allow arbitrary webpage loading by untrusted applications.
To mitigate CVE-2021-25439, upgrade Samsung Members to version 2.4.85.11 or later for Android O or version 3.9.10.11 or later for Android P.
CVE-2021-25439 affects Samsung Members applications prior to version 2.4.85.11 for Android O and prior to version 3.9.10.11 for Android P.
CVE-2021-25439 is characterized as an improper access control vulnerability.
Yes, CVE-2021-25439 can be exploited remotely by untrusted applications to manipulate webpage loading in webview.