Unrated severityNVD Advisory· Published Apr 9, 2021· Updated Aug 3, 2024
CVE-2021-25373
CVE-2021-25373
Description
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2prior to 2.2.02.1 on Android O, prior to 2.4.03.0 on Android P, prior to 2.7.02.1 on Android Q, prior to 2.9.01.1 on Android R+ 1 more
- (no CPE)range: prior to 2.2.02.1 on Android O, prior to 2.4.03.0 on Android P, prior to 2.7.02.1 on Android Q, prior to 2.9.01.1 on Android R
- (no CPE)range: Android O(8.x)
Patches
Vulnerability mechanics
References
2- security.samsungmobile.commitrex_refsource_CONFIRM
- security.samsungmobile.com/serviceWeb.smsbmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.