CVE-2024-20825: Medium severity Samsung Galaxy Store vulnerability
Published Feb 6, 2024
·Updated
Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
Affected Software
1 affected component
Samsung Galaxy Store<4.5.63.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Galaxy Store (IAP)to a version that resolves this vulnerability.Fixed in 4.5.63.6
Event History
Feb 6, 2024
CVE Published
via MITRE·02:23 AM
Data Sourced
via MITRE·02:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-20825?
CVE-2024-20825 has a medium severity level due to its potential impact on sensitive information.
2
How do I fix CVE-2024-20825?
To fix CVE-2024-20825, update the Galaxy Store to version 4.5.63.6 or later.
3
What software is affected by CVE-2024-20825?
CVE-2024-20825 affects Samsung Galaxy Store versions prior to 4.5.63.6.
4
What type of vulnerability is CVE-2024-20825?
CVE-2024-20825 is an implicit intent hijacking vulnerability in the In-App Purchase system.
5
Who can exploit CVE-2024-20825?
CVE-2024-20825 can be exploited by local attackers with access to the device.