Improper Access Control in Samsung S7 Pre-installed Application
CVE-2019-15444
7.8HIGH
Summary
The Samsung S7 exhibits a vulnerability within a pre-installed application, specifically the com.samsung.android.themecenter. This issue arises from malconfigured access controls that permit other pre-installed applications to exploit functions meant to be restricted. Apps that have been granted signatureOrSystem permissions can interact with the vulnerable app, leading to unauthorized app installation. Users should be aware of this risk and take necessary precautions to secure their devices.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved