CVE-2019-15454: High severity samsung galaxy j4 vulnerability
The Samsung J4 Android device with a build fingerprint of samsung/j4lteub/j4lte:8.0.0/R16NW/J400MUBU2ARL4:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15454?
CVE-2019-15454 has been classified as a medium severity vulnerability.
How do I fix CVE-2019-15454?
To mitigate CVE-2019-15454, ensure that your device is updated with the latest firmware from Samsung that addresses this vulnerability.
What devices are affected by CVE-2019-15454?
CVE-2019-15454 affects the Samsung Galaxy J4 Android device specifically.
What type of vulnerability is CVE-2019-15454?
CVE-2019-15454 is a vulnerability in a pre-installed application that could potentially allow unauthorized access to sensitive data.
Is there a workaround for CVE-2019-15454 if I cannot update my device?
If unable to update, consider disabling the vulnerable application if possible and avoid installing suspicious applications.