Medium severity5.5NVD Advisory· Published Apr 9, 2021· Updated Jun 17, 2026
CVE-2021-25373
CVE-2021-25373
Description
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:samsung:customization_service:*:*:*:*:*:*:*:*range: <2.2.02.1
- (no CPE)range: <2.2.02.1 (Android O), <2.4.03.0 (Android P), <2.7.02.1 (Android Q), <2.9.01.1 (Android R)
- (no CPE)range: Android O(8.x)
Patches
Vulnerability mechanics
References
2- security.samsungmobile.comnvdVendor Advisory
- security.samsungmobile.com/serviceWeb.smsbnvdVendor Advisory
News mentions
0No linked articles in our index yet.