Arbitrary Code Execution Vulnerability in Samsung Galaxy Apps
CVE-2018-10499
7HIGH
What is CVE-2018-10499?
A vulnerability in Samsung Galaxy Apps permits local attackers to execute arbitrary code due to insufficient validation of user-supplied URLs. To exploit this issue, an attacker must have the capability to run low-privileged code on the target device. The flaw emerges from the handling of URLs, allowing execution of arbitrary JavaScript that can lead to unauthorized application installations under the user's context, thereby posing significant security risks.
Affected Version(s)
Samsung Galaxy Apps Fixed in version 6.4.0.15