CVE-2023-21516
published 2023-05-26CVE-2023-21516: XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | galaxy_store | < 4.5.49.8 | 4.5.49.8 |
| samsung_mobile | galaxy_store | >= unspecified < 4.5.49.8 | 4.5.49.8 |