App Installation Vulnerability in Samsung J6 Device by Samsung
CVE-2019-15456
7.8HIGH
Summary
The Samsung J6 Android device has a vulnerability due to the pre-installed Theme Center app, which allows other pre-installed applications to perform unauthorized app installations. This occurs because the Theme Center exports capabilities that can be accessed by any pre-installed app with the appropriate permissions, potentially leading to security risks by enabling malicious installations.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved