Vulnerability in Samsung Android Device Allows Unauthorized App Installations
CVE-2019-15450

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
14 November 2019

Summary

The Samsung J3 Popeltecan Android device has a vulnerability due to a pre-installed application that permits other pre-installed apps to install apps without proper authorization. Specifically, the app package com.samsung.android.themecenter can be exploited by other apps with signature or system permissions, enabling them to access its installation capabilities. This flaw can lead to unauthorized app installations, posing security risks to the device and its users.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.