Android Device Vulnerability in Samsung J4 Allowing App Installation
CVE-2019-15453
7.8HIGH
Summary
The Samsung J4 Android device is compromised by a vulnerability present in the pre-installed Theme Center app. This flaw enables other pre-installed applications to initiate unauthorized installations through an accessible component, provided they possess the necessary signature or system permissions. Consequently, any app with these permissions could exploit this vulnerability to install malicious software without user consent, undermining the device's security and the user's privacy.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved