VYPR

Galaxy Themes

by Samsung Mobile

CVEs (5)

  • CVE-2022-28783MedMay 3, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

  • CVE-2021-25353MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.00

    Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Themes application without permission via hijacking the PendingIntent.

  • CVE-2026-21073MedAug 10, 2026
    risk 0.34cvss epss 0.00

    Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.

  • CVE-2024-20853MedApr 2, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrary files to sandbox of ThemeStore.

  • CVE-2022-28784MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.