CVE-2022-36871: Medium severity samsung pay vulnerability
Published Sep 9, 2022
·Updated
Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
Affected Software
2 affected components
Samsung Samsung Pay Android<5.1.47
Samsung Samsung Pay Kr Android<5.0.63
Event History
Sep 9, 2022
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-36871?
CVE-2022-36871 is rated as a medium severity vulnerability.
2
How do I fix CVE-2022-36871?
To fix CVE-2022-36871, update Samsung Pay to version 5.0.63 for KR or 5.1.47 for Global.
3
What platforms are affected by CVE-2022-36871?
CVE-2022-36871 affects Samsung Pay on Android devices prior to the specified versions.
4
What type of attack is associated with CVE-2022-36871?
CVE-2022-36871 involves a Pending Intent hijacking that allows unauthorized access to files.
5
Can attackers exploit CVE-2022-36871 remotely?
Yes, attackers can exploit CVE-2022-36871 remotely through implicit Intent.