Arbitrary Code Execution Vulnerability in Samsung Galaxy Apps
CVE-2018-10499

7HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
24 September 2018

Summary

A vulnerability in Samsung Galaxy Apps permits local attackers to execute arbitrary code due to insufficient validation of user-supplied URLs. To exploit this issue, an attacker must have the capability to run low-privileged code on the target device. The flaw emerges from the handling of URLs, allowing execution of arbitrary JavaScript that can lead to unauthorized application installations under the user's context, thereby posing significant security risks.

Affected Version(s)

Samsung Galaxy Apps Fixed in version 6.4.0.15

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.