Open redirect in Galaxy S21 - #VU60726
Published: February 21, 2022
Galaxy S21
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect victims to arbitrary URL.
The vulnerability exists due to improper sanitization of user-supplied data within the Galaxy Store. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain, leading to remote code execution.