An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.
Link | Tags |
---|---|
https://blog.oversecured.com/Two-weeks-of-securing-Samsung-devices-Part-1/ | third party advisory exploit |
https://security.samsungmobile.com/securityUpdate.smsb?year=2021&month=5 | vendor advisory |