Vulnerability in Samsung XCover4's Pre-installed App Allows Unauthorized App Installations
CVE-2019-15439
7.8HIGH
Summary
The Samsung XCover4 Android device is affected by a vulnerability in a pre-installed application, allowing other pre-installed apps the ability to initiate installations without user consent. This flaw arises from improper access control that permits apps with system-level permissions to leverage capabilities of the vulnerable app, potentially leading to unauthorized changes to the device's software landscape. Users should be aware of the risks associated with unregulated app installations and consider protective measures.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved