CVE-2022-28776Improper Authorization in Mobile Galaxy Store

Severity
7.8HIGHNVD
CNA5.9
EPSS
0.1%
top 84.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateApr 12

Description

Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDsamsung/galaxy_store< 4.5.36.4
CVEListV5samsung_mobile/galaxy_store-4.5.36.4

🔴Vulnerability Details

2
GHSA
GHSA-56qh-54mj-8vvx: Improper access control vulnerability in Galaxy Store prior to version 42022-04-12
CVEList
CVE-2022-28776: Improper access control vulnerability in Galaxy Store prior to version 42022-04-11
CVE-2022-28776 — Improper Authorization | cvebase