CVE-2021-25373

Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
OR cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

Information

Published : 2021-04-09 18:15

Updated : 2021-04-21 17:43


NVD link : CVE-2021-25373

Mitre link : CVE-2021-25373


JSON object : View

Products Affected

samsung

  • customization_service

google

  • android
CWE
CWE-863

Incorrect Authorization