CVE-2025-21079
BaseFortify
Publication date: 2025-11-05
Last updated on: 2025-11-07
Assigner: Samsung Mobile
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | members | to 5.5.01.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is due to improper input validation in Samsung Members versions prior to 5.5.01.3. It allows remote attackers to connect to arbitrary URLs and launch arbitrary activities with Samsung Members privileges. Exploitation requires user interaction to trigger the vulnerability.
How can this vulnerability impact me? :
An attacker could exploit this vulnerability to launch arbitrary activities within the Samsung Members app with its privileges, potentially leading to unauthorized actions or disruptions. Although it does not directly compromise confidentiality, it can impact integrity and availability of the affected system or app.