CVE ID | CVE-2024-49419, CVE-2024-49418 |
CVSS SCORE | 5.4, AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
AFFECTED VENDORS |
Samsung |
AFFECTED PRODUCTS |
Galaxy S24 |
VULNERABILITY DETAILS |
This vulnerability allows remote attackers to escalate privileges on affected installations of Samsung Galaxy S24 smartphones. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the Gaming Hub application. The issue results from the lack of proper validation of a user-supplied URL. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary script in the context of a WebView. |
ADDITIONAL DETAILS |
Samsung has issued an update to correct this vulnerability. More details can be found at:
https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=12 |
DISCLOSURE TIMELINE |
|
CREDIT | Ken Gannon of NCC Group (@yogehi) |