Samsung Android
cpe:2.3:o:samsung:android:*:*:*:*:*:*:*
- >= 11, < 12
- >= 12, < 13
- >= 13, < 14
A PendingIntent hijacking vulnerability has been identified in the CertificatePolicy component of the Android framework, affecting versions prior to the April 2023 Security Maintenance Release. This vulnerability allows local attackers to access a ContentProvider without the necessary permissions. The issue arises from improper handling of PendingIntents, which can be exploited to bypass authorization requirements and access sensitive data or functionality.
Exploitation of this vulnerability could lead to unauthorized access to ContentProviders, allowing attackers to read or modify data without proper permissions.
Users can apply the April 2023 Security Maintenance Release to address this vulnerability. Instructions for downloading this update are available on the Samsung Mobile Security Update page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.