First published: Fri Sep 09 2022(Updated: )
Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Samsung Pay | <5.1.47 | |
Samsung Samsung Pay Kr | <5.0.63 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36872 is classified as a high severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2022-36872, update Samsung Pay to version 5.0.63 for KR or 5.1.47 for Global.
CVE-2022-36872 is a Pending Intent hijacking vulnerability that affects Samsung Pay.
CVE-2022-36872 affects versions of Samsung Pay prior to 5.0.63 for KR and 5.1.47 for Global.
Attackers exploiting CVE-2022-36872 can access files without permission via implicit Intent.