CVE-2025-20951

Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:galaxy_store:*:*:*:*:*:*:*:*

History

17 Jul 2025, 18:16

Type Values Removed Values Added
CWE NVD-CWE-Other
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=04 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2025&month=04 - Vendor Advisory
First Time Samsung
Samsung galaxy Store
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:samsung:galaxy_store:*:*:*:*:*:*:*:*

08 Apr 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 05:15

Updated : 2025-07-17 18:16


NVD link : CVE-2025-20951

Mitre link : CVE-2025-20951


JSON object : View

Products Affected

samsung

  • galaxy_store