mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
18 lines
1.0 KiB
Markdown
18 lines
1.0 KiB
Markdown
### [CVE-2019-15458](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15458)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Samsung J7 Neo Android device with a build fingerprint of samsung/j7veltedx/j7velte:8.1.0/M1AJQ/J701FXXS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app installation via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.kryptowire.com/android-firmware-2019/
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|