First published: Fri May 26 2023(Updated: )
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy Store | <4.5.49.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21515 is a vulnerability in the InstantPlay script in Galaxy Store prior to version 4.5.49.8 that allows attackers to execute JavaScript API to install APKs.
CVE-2023-21515 has a severity rating of 8.8 (high severity).
CVE-2023-21515 allows attackers to execute JavaScript API in the Galaxy Store prior to version 4.5.49.8, potentially leading to the installation of malicious APKs.
To fix CVE-2023-21515, users should update their Galaxy Store app to version 4.5.49.8 or newer.
You can find more information about CVE-2023-21515 on the Samsung Mobile Security website: https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=01