Samsung SecEmailComposer QUICK_REPLY_BACKGROUND Permission Weakness
Posted by deepcore on October 28, 2015 – 12:52 pm
The SecEmailComposer/EmailComposer application used by the Samsung S6 Edge has an exported service action to do quick replies to emails. It was found that this action required no permissions to call, and could lead to an unprivileged application gaining access to email content.
Post a reply
You must be logged in to post a comment.