PT-2022-13731 · Samsung · Samsung Galaxy S21
S_N_T
+1
·
Published
2022-04-12
·
Updated
2023-04-04
·
CVE-2022-1230
CVSS v3.1
3.9
Low
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung Galaxy S21 versions prior to 4.5.40.5
Description
This issue allows local attackers to execute arbitrary code on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this issue. The specific flaw exists within the handling of redirections. An attacker can force a redirection to a site that serves malicious content. This can be leveraged in conjunction with other issues to escalate privileges and execute arbitrary code in the context of the current user.
Recommendations
For versions prior to 4.5.40.5, update to version 4.5.40.5 or later to resolve the issue. As a temporary workaround, consider restricting access to sites that may serve malicious content to minimize the risk of exploitation. Avoid using the loadUrl function until the issue is resolved.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Galaxy S21