Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
2021-04-09T18:15:15.023
2024-11-21T05:54:51.813
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | samsung | customization_service | < 2.2.02.1 | Yes |
Operating System | android | 8.0 | No | |
Operating System | android | 8.1 | No | |
Application | samsung | customization_service | < 2.4.03.0 | Yes |
Operating System | android | 9.0 | No | |
Application | samsung | customization_service | < 2.7.02.1 | Yes |
Operating System | android | 10.0 | No | |
Application | samsung | customization_service | < 2.9.01.1 | Yes |
Operating System | android | 11.0 | No |