Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://security.samsungmobile.com/ | vendor advisory |
https://security.samsungmobile.com/serviceWeb.smsb | vendor advisory |