First published: Mon Jul 11 2022(Updated: )
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy Store | <4.5.41.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-33708 is classified as a high-severity vulnerability due to improper input validation allowing activity launches with elevated privileges.
To fix CVE-2022-33708, update the Galaxy Store to version 4.5.41.8 or later.
CVE-2022-33708 affects users of Samsung Galaxy Store prior to version 4.5.41.8.
Local attackers can exploit CVE-2022-33708 to launch activities with Galaxy Store privileges.
There is no known workaround for CVE-2022-33708; the only mitigation is to update to the latest software version.