#VU60726 Open redirect in Galaxy S21
Published: February 21, 2022
Galaxy S21
Samsung
Description
The vulnerability allows a remote attacker to redirect victims to arbitrary URL.
The vulnerability exists due to improper sanitization of user-supplied data within the Galaxy Store. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain, leading to remote code execution.