CVE-2023-21433
published 2023-02-09CVE-2023-21433: Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
3.67%
88.4th percentile
Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | galaxy_store | < 4.5.49.8 | 4.5.49.8 |
| samsung_mobile | galaxy_store | >= unspecified < 4.5.49.8 | 4.5.49.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Checkpoint
23rd January – Threat Intelligence Report
blogs_checkpoint·2023-01-23·CVSS 9.8
CVE-2022-42475 [CRITICAL] 23rd January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 23rd January, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
The fast food brand ‘Yum! Brands’, operator of leading fast food restaurants including KFC, Pizza Hut and Taco Bell, has been targeted by a ransomware attack. The attack lead to the temporary closure of almost 300 breaches in the United Kingdom. No group has taken claim at this point.
Vice Society ransomware gang has claim
Bugzilla
Opening intents without asking puts Firefox users at risk of any known exploit in any intent-addressable app that hasn't been patched
bugzilla·2023-01-17
Opening intents without asking puts Firefox users at risk of any known exploit in any intent-addressable app that hasn't been patched
Opening intents without asking puts Firefox users at risk of any known exploit in any intent-addressable app that hasn't been patched
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
Steps to reproduce:
1. Visit [exploit](https://kirtikumarar.com/1.html)
2. Click on the hyperlink
Actual results:
The browser will redirect to the target app without notifying the User and use the available Chromium exploit to trigger RCE there.
Expected results:
It should check and ask if the user wants to be redirected to Samsung Internet
Discussion:
The bug was marked "in-the-wild" here: https://bugs.chromium.org/p/chromium/issues/detail?id=1345630
A similar bug was exploited in the wild in the Firefox browser https://bug
2023-02-09
Published