Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2021-25374

Description

An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.

POC

Reference

- https://security.samsungmobile.com/serviceWeb.smsb

Github

- https://github.com/ARPSyndicate/cve-scores

- https://github.com/ARPSyndicate/cvemon

- https://github.com/FSecureLABS/CVE-2021-25374_Samsung-Account-Access

- https://github.com/NaInSec/CVE-PoC-in-GitHub

- https://github.com/ReversecLabs/CVE-2021-25374_Samsung-Account-Access

- https://github.com/SYRTI/POC_to_review

- https://github.com/WhooAmii/POC_to_review

- https://github.com/WithSecureLabs/CVE-2021-25374_Samsung-Account-Access

- https://github.com/k0mi-tg/CVE-POC

- https://github.com/manas3c/CVE-POC

- https://github.com/nomi-sec/PoC-in-GitHub

- https://github.com/soosmile/POC

- https://github.com/trhacknon/Pocingit

- https://github.com/whoforget/CVE-POC

- https://github.com/youwizard/CVE-POC

- https://github.com/zecool/cve