Improper Component Export in GoodLock by Samsung
CVE-2024-34598

7.7HIGH

Key Information:

Vendor

Samsung

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2024-34598?

A security flaw in Samsung's GoodLock application, prior to version 2.2.04.95, enables local attackers to exploit improper export of components, leading to the installation of arbitrary applications from the Galaxy Store. This vulnerability exposes users to significant security risks by allowing unauthorized applications to run on their devices, potentially compromising personal data and device integrity.

Affected Version(s)

GoodLock 2.2.04.95

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-34598 : Improper Component Export in GoodLock by Samsung