Arbitrary Code Execution Vulnerability in Samsung Galaxy Apps
CVE-2018-10499
7HIGH
Summary
A vulnerability in Samsung Galaxy Apps permits local attackers to execute arbitrary code due to insufficient validation of user-supplied URLs. To exploit this issue, an attacker must have the capability to run low-privileged code on the target device. The flaw emerges from the handling of URLs, allowing execution of arbitrary JavaScript that can lead to unauthorized application installations under the user's context, thereby posing significant security risks.
Affected Version(s)
Samsung Galaxy Apps Fixed in version 6.4.0.15
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved