Impact
Improper access control in Galaxy Store prior to version 4.6.03.8 allows a local attacker to create a file with the same privilege level as the application. This flaw permits the attacker to create or modify files that the Galaxy Store process can read or write, potentially enabling actions that require elevated privileges. The vulnerability is limited to code that runs locally on the device.
Affected Systems
Samsung mobile devices running Galaxy Store versions older than 4.6.03.8 on any Android release that includes the vulnerable component.
Risk and Exploitability
The CVSS score of 7 indicates high severity, while the EPSS score of less than 1 percent suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, reducing the urgency for widespread incidents. Exploitation requires a local attacker with the ability to execute code on the device, and no public exploits have been reported.
OpenCVE Enrichment