Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year==2022&month=07 | vendor advisory |