Android Device Vulnerability in Samsung J4 Allowing App Installation
CVE-2019-15453

7.8HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
14 November 2019

Summary

The Samsung J4 Android device is compromised by a vulnerability present in the pre-installed Theme Center app. This flaw enables other pre-installed applications to initiate unauthorized installations through an accessible component, provided they possess the necessary signature or system permissions. Consequently, any app with these permissions could exploit this vulnerability to install malicious software without user consent, undermining the device's security and the user's privacy.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.