CVE-2018-21081

CRITICAL

Samsung Android N(7.x) - Unauthorized Permission Assignment in Dual Messenger

Title source: llm
STIX 2.1

Description

An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the second app can use the runtime permissions of the first app without a user's consent. The Samsung ID is SVE-2017-11018 (March 2018).

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/securityUpdate.smsb

Scores

CVSS v3 9.1
EPSS 0.0039
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-732
Status published
Products (4)
google/android 7.0
google/android 7.1.0
google/android 7.1.1
google/android 7.1.2
Published Apr 08, 2020
Tracked Since Feb 18, 2026