An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.
2021-04-09T18:15:15.100
2024-11-21T05:54:51.950
Modified
CVSSv3.1: 8.6 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | samsung | members | ≤ 2.4.83.9 | Yes |
Operating System | android | 8.1 | No | |
Application | samsung | members | ≥ 3.9.00.9 | Yes |
Operating System | android | 9.0 | No |