Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
History

Thu, 17 Jul 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung galaxy Store
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:samsung:galaxy_store:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung galaxy Store

Tue, 08 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 04:45:00 +0000

Type Values Removed Values Added
Description Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published: 2025-04-08T04:40:05.996Z

Updated: 2025-04-08T15:30:09.445Z

Reserved: 2024-11-06T02:30:14.864Z

Link: CVE-2025-20951

cve-icon Vulnrichment

Updated: 2025-04-08T15:15:21.267Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-08T05:15:39.647

Modified: 2025-07-17T18:16:16.397

Link: CVE-2025-20951

cve-icon Redhat

No data.