Potential Security Risk in Samsung J7 Neo Android Device and Pre-Installed Apps
CVE-2019-15458
7.8HIGH
Summary
The Samsung J7 Neo Android device contains a pre-installed app, com.samsung.android.themecenter, that allows other pre-installed apps to perform unauthorized app installations through an accessible app component. Any pre-installed app that gains signature or system permissions can exploit this capability, leading to security risks. This flaw underscores the importance of robust access controls in mobile applications.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved