Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
History

Tue, 08 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 04:45:00 +0000

Type Values Removed Values Added
Description Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2025-04-08T15:30:09.445Z

Reserved: 2024-11-06T02:30:14.864Z

Link: CVE-2025-20951

cve-icon Vulnrichment

Updated: 2025-04-08T15:15:21.267Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T05:15:39.647

Modified: 2025-04-08T18:13:53.347

Link: CVE-2025-20951

cve-icon Redhat

No data.