CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-20825: Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via...

5.5 CVSS

Description

Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Classification

CVE ID: CVE-2024-20825

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.5

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Problem Types

CWE-927 : Use of Implicit Intent for Sensitive Communication

Affected Products

Vendor: Samsung Mobile

Product: Galaxy Store

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 10.72% (scored less or equal to compared to others)

EPSS Date: 2025-06-13 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-20825
https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=02

Timeline