Severity
7.8HIGH
EPSS
0.0%
top 90.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12
Latest updateJul 13

Description

Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDsamsung/galaxy_store< 4.5.41.8
CVEListV5samsung_mobile/galaxy_storeunspecified4.5.41.8

🔴Vulnerability Details

2
GHSA
GHSA-gqv7-wg8q-m48q: Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 42022-07-13
CVEList
CVE-2022-33709: Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 42022-07-11
CVE-2022-33709 (HIGH CVSS 7.8) | Improper input validation vulnerabi | cvebase.io