Unauthorized App Installation via Pre-Installed Samsung Application
CVE-2019-15437

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
14 November 2019

Summary

The Samsung XCover4, with specific build fingerprints, contains a pre-installed app that allows other apps on the device to perform unauthorized installations. This vulnerability arises from the accessibility of an app component, enabling any pre-installed application with the necessary permissions to exploit this capability. This can lead to potential security risks as it allows for manipulation of app installations without user consent.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.