Vulnerability in Samsung Android Device Allows Unauthorized App Installations
CVE-2019-15450
7.8HIGH
Summary
The Samsung J3 Popeltecan Android device has a vulnerability due to a pre-installed application that permits other pre-installed apps to install apps without proper authorization. Specifically, the app package com.samsung.android.themecenter can be exploited by other apps with signature or system permissions, enabling them to access its installation capabilities. This flaw can lead to unauthorized app installations, posing security risks to the device and its users.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved