CVE-2021-25403

LOW

Samsung Account <10.8.0.4-12.2.0.9 - SSRF

Title source: llm
STIX 2.1

Description

Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.

References (1)

Core 1
Core References

Scores

CVSS v3 3.3
EPSS 0.0006
EPSS Percentile 20.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
samsung/account 12.2.0.9
samsung/account < 10.8.0.4
Published Jun 11, 2021
Tracked Since Feb 18, 2026