# N/A
## 漏洞概述
三星Members "samsungrewards" 深链接中存在授权不当漏洞,允许远程攻击者访问与Samsung Account相关的用户数据。
## 影响版本
- Android O(8.1)及以下版本:2.4.83.9
- Android P(9.0)及以上版本:3.9.00.9
## 漏洞细节
该漏洞存在于三星会员系统("samsungrewards")的深链接功能中,由于授权机制不当,远程攻击者可以利用这一漏洞访问用户与Samsung Account相关的数据。
## 影响
远程攻击者可以利用此漏洞访问用户的Sensitive Data(敏感数据),这将导致用户隐私泄露。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | This script can be used to gain access to a victim's Samsung Account if they have a specific version of Samsung Members installed on their Samsung Device, and if the victim's device is from the US or Korea region. | https://github.com/WithSecureLabs/CVE-2021-25374_Samsung-Account-Access | POC详情 |
2 | This script can be used to gain access to a victim's Samsung Account if they have a specific version of Samsung Members installed on their Samsung Device, and if the victim's device is from the US or Korea region. | https://github.com/ReversecLabs/CVE-2021-25374_Samsung-Account-Access | POC详情 |
暂无评论