CVE-2026-21002: Medium severity Samsung Galaxy Store vulnerability
Published Mar 16, 2026
·Updated
Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.
Affected Software
2 affected components
Samsung Galaxy Store<4.6.03.8
Samsung Galaxy Store<4.6.03.8
Event History
Mar 16, 2026
CVE Published
via MITRE·04:32 AM
Data Sourced
via MITRE·04:32 AM
DescriptionWeakness
Data Sourced
via NVD·02:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21002?
CVE-2026-21002 has a medium severity rating due to the potential for local attackers to install arbitrary applications.
2
How do I fix CVE-2026-21002?
To fix CVE-2026-21002, update the Galaxy Store application to version 4.6.03.8 or later.
3
Who is affected by CVE-2026-21002?
Users of Samsung Galaxy Store prior to version 4.6.03.8 are affected by CVE-2026-21002.
4
What type of attack is possible due to CVE-2026-21002?
CVE-2026-21002 allows a local attacker to install arbitrary applications on the affected device.
5
When was CVE-2026-21002 reported?
CVE-2026-21002 was reported in March 2026.