App Installation Vulnerability in Samsung Android Devices
CVE-2019-15446

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
14 November 2019

Summary

The Samsung S7 Android device harbors a vulnerability due to a pre-installed app that allows any other pre-installed app to initiate app installation via an accessible component. This flaw arises when pre-installed applications obtain the necessary permissions to exploit exported functionalities, potentially leading to unauthorized app installations. The affected version is known for its build fingerprint, which specifies the vulnerable conditions under which the exploit may occur. It's crucial for users to be aware of this vulnerability, as it may jeopardize the integrity of their devices.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.