Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://security.samsungmobile.com/ | vendor advisory |
https://security.samsungmobile.com/serviceWeb.smsb | vendor advisory |