First published: Mon Apr 11 2022(Updated: )
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy Store | <4.5.40.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28544 is a high-severity vulnerability that exposes the Galaxy Store to path traversal attacks.
To fix CVE-2022-28544, update the Galaxy Store to version 4.5.40.5 or later.
CVE-2022-28544 affects all versions of Galaxy Store prior to version 4.5.40.5.
CVE-2022-28544 allows attackers to exploit a path traversal vulnerability to access sensitive files within the Galaxy Store.
Users of Samsung Galaxy Store versions below 4.5.40.5 are vulnerable to CVE-2022-28544.