cbcvebase.
CVE-2021-25403
published 2021-06-11

CVE-2021-25403: Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows…

low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.

Affected

3 ranges
VendorProductVersion rangeFixed in
samsungaccount< 10.8.0.410.8.0.4
samsungaccount
samsung_mobilesamsung_account>= unspecified < 10.8.0.4 in Android P(9.0) below, and 12.2.0.9 in Android Q(10.0) above10.8.0.4 in Android P(9.0) below, and 12.2.0.9 in Android Q(10.0) above
CVE-2021-25403 — Sensitive Information Exposure | cvebase