CVE-2024-20853

MEDIUM

ThemeStore <5.3.05.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrary files to sandbox of ThemeStore.

References (1)

Core 1

Scores

CVSS v3 5.1
EPSS 0.0008
EPSS Percentile 24.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
samsung/galaxy_themes < 5.3.05.2
Published Apr 02, 2024
Tracked Since Feb 18, 2026