PT-2021-16550 · Google · Android
Published
2021-04-09
·
Updated
2022-04-26
·
CVE-2021-25357
CVSS v3.1
5.6
Medium
| Vector | AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Create Movie versions prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0)
Create Movie version 3.4.81.1 in Android Q(10.0)
Create Movie version 3.6.80.7 in Android R(11.0)
Description:
A pendingIntent hijacking issue allows unprivileged applications to access contact information.
Recommendations:
For Create Movie versions prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), update to a version after SMR APR-2021 Release 1.
For Create Movie version 3.4.81.1 in Android Q(10.0), update to a version later than 3.4.81.1.
For Create Movie version 3.6.80.7 in Android R(11.0), update to a version later than 3.6.80.7.
Fix
Information Disclosure
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android