First published: Fri Jan 07 2022(Updated: )
A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to execute privileged action by hijacking and modifying the intent.
Credit: mobile.security@samsung.com mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Reminder | <12.2.05.0 | |
Google Android | =11.0 | |
Samsung Reminder | <12.3.02.1000 | |
Google Android | =12.0 | |
All of | ||
Samsung Reminder | <12.2.05.0 | |
Google Android | =11.0 | |
All of | ||
Samsung Reminder | <12.3.02.1000 | |
Google Android | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22285 is considered a high severity vulnerability due to its ability to allow attackers to execute privileged actions.
To fix CVE-2022-22285, users should update Samsung Reminder to versions 12.2.05.0 or later.
CVE-2022-22285 affects Samsung Reminder versions prior to 12.2.05.0 on Android R (11.0) and prior to 12.3.02.1000 on Android S (12.0).
CVE-2022-22285 exploits the PendingIntent feature in Samsung Reminder, allowing intent hijacking.
Users of Samsung Reminder on vulnerable Android versions are at risk from CVE-2022-22285.