Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://security.samsungmobile.com | vendor advisory |
https://security.samsungmobile.com/serviceWeb.smsb | vendor advisory |