Weakness in Pre-installed App on Samsung Android Devices
CVE-2019-15441
7.8HIGH
Summary
A security vulnerability exists in specific Samsung Android devices, notably those utilizing the on7xeltelgt build fingerprint. This vulnerability involves a pre-installed application, com.samsung.android.themecenter, which permits other pre-installed applications to initiate installation processes through an accessible component. This mechanism poses a risk as any app with signatureOrSystem permissions can exploit this feature, potentially leading to unauthorized app installations without user consent, highlighting significant security concerns for affected devices.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved