PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Sep 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android Samsung Samsung mobile Samsung samsung Mobile |
|
Vendors & Products |
Google
Google android Samsung Samsung mobile Samsung samsung Mobile |
Wed, 03 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-287 | |
Metrics |
ssvc
|
Wed, 03 Sep 2025 05:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission. | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: SamsungMobile
Published: 2025-09-03T05:16:58.350Z
Updated: 2025-09-03T15:44:11.986Z
Reserved: 2022-11-14T08:58:53.180Z
Link: CVE-2023-21466

Updated: 2025-09-03T14:11:41.663Z

Status : Received
Published: 2025-09-03T06:15:38.243
Modified: 2025-09-03T16:15:32.263
Link: CVE-2023-21466

No data.