#VU83880 Input validation error in Galaxy Store - CVE-2023-42581
Published: December 5, 2023 / Updated: June 25, 2024
Galaxy Store
Samsung
Description
The vulnerability allows a remote attacker to compromise the affected device.
The vulnerability exists due to insufficient validation of URL passed from InstantPlay deeplink. A remote attacker can trick the victim to open a specially crafted URL and execute arbitrary JavaScript API to install APK from Galaxy Store.