CVE-2024-20870

Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:galaxy_store:*:*:*:*:*:*:*:*

History

17 Jul 2025, 19:59

Type Values Removed Values Added
CPE cpe:2.3:a:samsung:galaxy_store:*:*:*:*:*:*:*:*
CWE NVD-CWE-Other
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=05 - Vendor Advisory
First Time Samsung
Samsung galaxy Store

Information

Published : 2024-05-07 05:15

Updated : 2025-07-17 19:59


NVD link : CVE-2024-20870

Mitre link : CVE-2024-20870

CVE.ORG link : CVE-2024-20870


JSON object : View

Products Affected

samsung

  • galaxy_store