Open redirect in Galaxy S21 - #VU60726

 

Open redirect in Galaxy S21 - #VU60726

Published: February 21, 2022


Vulnerability identifier: #VU60726
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect victims to arbitrary URL.

The vulnerability exists due to improper sanitization of user-supplied data within the Galaxy Store. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain, leading to remote code execution.


Affected software

Galaxy S21

Remediation

Install updates from vendor's website.


External References

Related Security Bulletins