First published: Fri Sep 09 2022(Updated: )
Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Pay | <5.1.47 | |
Samsung Pay | <5.0.63 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36870 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to files.
To fix CVE-2022-36870, update Samsung Pay to version 5.0.63 or later for KR users and version 5.1.47 or later for Global users.
CVE-2022-36870 allows attackers to access files without permission through implicit Intent due to a Pending Intent hijacking vulnerability.
Samsung Pay versions prior to 5.0.63 for KR and earlier than 5.1.47 for Global are affected by CVE-2022-36870.
Yes, CVE-2022-36870 specifically affects Samsung Pay versions for KR and Global regions.