CVE-2021-25373

Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
OR cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-04-09 18:15

Updated : 2024-11-21 05:54


NVD link : CVE-2021-25373

Mitre link : CVE-2021-25373

CVE.ORG link : CVE-2021-25373


JSON object : View

Products Affected

google

  • android

samsung

  • customization_service
CWE
CWE-285

Improper Authorization

NVD-CWE-noinfo