High severity7.8NVD Advisory· Published Jul 8, 2021· Updated Jun 17, 2026
CVE-2021-25438
CVE-2021-25438
Description
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:samsung:members:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:samsung:members:*:*:*:*:*:*:*:*range: <2.4.85.11
- cpe:2.3:a:samsung:members:3.9.10.11:*:*:*:*:*:*:*
<2.4.85.11 (Android O(8.1) and below), <3.9.10.11 (Android P(9.0) and above)+ 1 more
- (no CPE)range: <2.4.85.11 (Android O(8.1) and below), <3.9.10.11 (Android P(9.0) and above)
- (no CPE)range: -
Patches
Vulnerability mechanics
References
1- security.samsungmobile.com/serviceWeb.smsbnvdVendor Advisory
News mentions
0No linked articles in our index yet.