Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10074 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Jul 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Samsung
Samsung galaxy Store |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:samsung:galaxy_store:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Samsung
Samsung galaxy Store |
Tue, 08 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SamsungMobile
Published:
Updated: 2025-04-08T15:30:09.445Z
Reserved: 2024-11-06T02:30:14.864Z
Link: CVE-2025-20951
Updated: 2025-04-08T15:15:21.267Z
Status : Analyzed
Published: 2025-04-08T05:15:39.647
Modified: 2025-07-17T18:16:16.397
Link: CVE-2025-20951
No data.
OpenCVE Enrichment
No data.
EUVD