First published: Fri Sep 09 2022(Updated: )
Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Samsung Pay | <5.1.47 | |
Samsung Samsung Pay Kr | <5.0.63 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36871 is rated as a medium severity vulnerability.
To fix CVE-2022-36871, update Samsung Pay to version 5.0.63 for KR or 5.1.47 for Global.
CVE-2022-36871 affects Samsung Pay on Android devices prior to the specified versions.
CVE-2022-36871 involves a Pending Intent hijacking that allows unauthorized access to files.
Yes, attackers can exploit CVE-2022-36871 remotely through implicit Intent.