SB2024040245 - Privilege escalation in Samsung ThemeStore
Published: April 2, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Verification of Intent by Broadcast Receiver (CVE-ID: CVE-2024-20853)
The vulnerability allows a local application to compromise the affected device.
The vulnerability exists due to improper verification of intent by broadcast receiver. A local application can write arbitrary files to sandbox of ThemeStore.
Remediation
Install update from vendor's website.