NA - CVE-2024-49411 - Path Traversal in ThemeCenter prior to SMR...
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
NA - CVE-2024-49412 - Improper input validation in Settings prior to...
Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.
NA - CVE-2024-49413 - Improper Verification of Cryptographic...
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.
NA - CVE-2024-49414 - Authentication Bypass Using an Alternate Path...
Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.
NA - CVE-2024-49417 - Use of implicit intent for sensitive...
Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this...
NA - CVE-2024-49418 - Insufficient verification of url authenticity...
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.
NA - CVE-2024-49419 - Insufficient verification of url authenticity...
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview.