CVE-2023-42581: Input Validation
Published Dec 5, 2023
·Updated
Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.
Affected Software
1 affected component
Samsung Galaxy Store<4.5.64.4
Event History
Dec 5, 2023
CVE Published
02:44 AM
Data Sourced
02:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-42581?
CVE-2023-42581 has been classified as a high severity vulnerability due to its potential to allow unauthorized access to data.
2
How do I fix CVE-2023-42581?
To fix CVE-2023-42581, update the Galaxy Store to version 4.5.64.4 or later.
3
What does CVE-2023-42581 exploit?
CVE-2023-42581 exploits improper URL validation from InstantPlay deeplink in the Galaxy Store.
4
What versions of Galaxy Store are affected by CVE-2023-42581?
CVE-2023-42581 affects all versions of the Galaxy Store prior to 4.5.64.4.
5
What can attackers do with CVE-2023-42581?
Attackers can execute JavaScript API through CVE-2023-42581, allowing access to sensitive user data.