CVE-2021-25352

MEDIUM

Bixby Voice <3.0.52.14 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://security.samsungmobile.com/
Vendor Advisory x_refsource_confirm
https://security.samsungmobile.com/serviceWeb.smsb

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 11.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-285 CWE-668
Status published
Products (1)
samsung/bixby_voice < 3.0.52.14
Published Mar 25, 2021
Tracked Since Feb 18, 2026