PT-2024-18732 · Samsung · Galaxy Store

Published

2024-02-05

·

Updated

2024-02-09

·

CVE-2024-20825

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Galaxy Store versions prior to 4.5.63.6
Description The issue allows local attackers to access sensitive information via implicit intent due to an implicit intent hijacking vulnerability in the In-App Purchase (IAP) component of the Galaxy Store. This vulnerability can be exploited by local attackers.
Recommendations For Galaxy Store versions prior to 4.5.63.6, update to version 4.5.63.6 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information within the Galaxy Store until the update is applied.

Fix

Related Identifiers

CVE-2024-20825

Affected Products

Galaxy Store