A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), and 3.6.80.7 in Android R(11.0) allows unprivileged applications to access contact information.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/securityUpdate.smsb | Vendor Advisory |
https://security.samsungmobile.com/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-04-09 11:15
Updated : 2022-04-26 09:02
NVD link : CVE-2021-25357
Mitre link : CVE-2021-25357
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
- android