CVE-2024-34598
BaseFortify
Publication date: 2025-09-04
Last updated on: 2025-09-04
Assigner: Samsung Mobile
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | goodlock | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an improper export of a component in the GoodLock application prior to version 2.2.04.95. It allows local attackers to install arbitrary applications from the Galaxy Store without proper authorization.
How can this vulnerability impact me? :
An attacker with local access could exploit this vulnerability to install unauthorized applications on your device, potentially leading to compromised device integrity, unauthorized actions, or disruption of service.
What immediate steps should I take to mitigate this vulnerability?
Update GoodLock to version 2.2.04.95 or later to fix the improper export of component vulnerability that allows local attackers to install arbitrary applications from Galaxy Store.