PT-2022-13731 · Samsung · Samsung Galaxy S21

S_N_T

+1

·

Published

2022-04-12

·

Updated

2023-04-04

·

CVE-2022-1230

CVSS v3.1

3.9

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Samsung Galaxy S21 versions prior to 4.5.40.5
Description This issue allows local attackers to execute arbitrary code on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this issue. The specific flaw exists within the handling of redirections. An attacker can force a redirection to a site that serves malicious content. This can be leveraged in conjunction with other issues to escalate privileges and execute arbitrary code in the context of the current user.
Recommendations For versions prior to 4.5.40.5, update to version 4.5.40.5 or later to resolve the issue. As a temporary workaround, consider restricting access to sites that may serve malicious content to minimize the risk of exploitation. Avoid using the loadUrl function until the issue is resolved.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2022-1230
ZDI-22-621

Affected Products

Samsung Galaxy S21