CVE-2023-21515: Input Validation
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-21515?
CVE-2023-21515 is a vulnerability in the InstantPlay script in Galaxy Store prior to version 4.5.49.8 that allows attackers to execute JavaScript API to install APKs.
How severe is CVE-2023-21515?
CVE-2023-21515 has a severity rating of 8.8 (high severity).
How does CVE-2023-21515 impact Samsung Galaxy Store?
CVE-2023-21515 allows attackers to execute JavaScript API in the Galaxy Store prior to version 4.5.49.8, potentially leading to the installation of malicious APKs.
How can I fix CVE-2023-21515?
To fix CVE-2023-21515, users should update their Galaxy Store app to version 4.5.49.8 or newer.
Where can I find more information about CVE-2023-21515?
You can find more information about CVE-2023-21515 on the Samsung Mobile Security website: https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=01