Samsung Galaxy Store vulnerabilities
31 known vulnerabilities affecting samsung/galaxy_store.
Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH10MEDIUM18LOW1
Vulnerabilities
Page 1 of 2
CVE-2023-42580P3CRITICALCVSS 9.8fixed in 4.5.64.42023-12-05
CVE-2023-42580 [CRITICAL] CVE-2023-42580: Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows att
Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.
nvd
CVE-2023-21514P3HIGHCVSS 8.8fixed in 4.5.49.82023-05-26
CVE-2023-21514 [HIGH] CWE-20 CVE-2023-21514: Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allow
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
nvd
CVE-2023-42581P3HIGHCVSS 7.5fixed in 4.5.64.42023-12-05
CVE-2023-42581 [HIGH] CVE-2023-42581: Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows a
Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.
nvd
CVE-2023-21433P3HIGHCVSS 7.8fixed in 4.5.49.82023-02-09
CVE-2023-21433 [HIGH] CWE-285 CVE-2023-21433: Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attacke
Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.
nvd
CVE-2026-20976P3HIGHCVSS 7.8fixed in 4.6.02.02026-01-09
CVE-2026-20976 [HIGH] CVE-2026-20976: Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute a
Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.
nvd
CVE-2023-21515P3HIGHCVSS 8.8fixed in 4.5.49.82023-05-26
CVE-2023-21515 [HIGH] CWE-20 CVE-2023-21515: InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
nvd
CVE-2022-22288P3HIGHCVSS 7.5fixed in 4.5.36.52022-01-10
CVE-2022-22288 [HIGH] CWE-285 CVE-2022-22288: Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installatio
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
nvd
CVE-2022-28776P3HIGHCVSS 7.8fixed in 4.5.36.42022-04-11
CVE-2022-28776 [HIGH] CWE-285 CVE-2022-28776: Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to i
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.
nvd
CVE-2023-21516P3CRITICALCVSS 9.6fixed in 4.5.49.82023-05-26
CVE-2023-21516 [CRITICAL] CWE-20 CVE-2023-21516: XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to exe
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
nvd
CVE-2022-33708P3HIGHCVSS 7.8fixed in 4.5.41.82022-07-12
CVE-2022-33708 [HIGH] CWE-20 CVE-2022-33708: Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
nvd
CVE-2022-33709P3HIGHCVSS 7.8fixed in 4.5.41.82022-07-12
CVE-2022-33709 [HIGH] CWE-20 CVE-2022-33709: Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
nvd
CVE-2022-33710P3HIGHCVSS 7.8fixed in 4.5.41.82022-07-12
CVE-2022-33710 [HIGH] CWE-20 CVE-2022-33710: Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version
Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
nvd
CVE-2023-21434P4MEDIUMCVSS 6.1fixed in 4.5.49.82023-02-09
CVE-2023-21434 [MEDIUM] CWE-20 CVE-2023-21434: Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attac
Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.
nvd
CVE-2022-28544P4MEDIUMCVSS 5.5fixed in 4.5.40.52022-04-11
CVE-2022-28544 [MEDIUM] CWE-22 CVE-2022-28544: Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to ve
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.
nvd
CVE-2025-20951P4MEDIUMCVSS 5.5fixed in 4.5.90.72025-04-08
CVE-2025-20951 [MEDIUM] CVE-2025-20951: Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
nvd
CVE-2026-21002P4MEDIUMCVSS 5.5fixed in 4.6.03.82026-03-16
CVE-2026-21002 [MEDIUM] CWE-347 CVE-2026-21002: Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows lo
Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.
nvd
CVE-2024-20870P4MEDIUMCVSS 5.5fixed in 4.5.71.82024-05-07
CVE-2024-20870 [MEDIUM] CVE-2024-20870: Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
nvd
CVE-2026-21000P4MEDIUMCVSS 5.5fixed in 4.6.03.82026-03-16
CVE-2026-21000 [MEDIUM] CWE-22 CVE-2026-21000: Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create fi
Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
nvd
CVE-2026-21001P4MEDIUMCVSS 5.5fixed in 4.6.03.82026-03-16
CVE-2026-21001 [MEDIUM] CWE-22 CVE-2026-21001: Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with G
Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
nvd
CVE-2023-21483P4MEDIUMCVSS 5.5fixed in 4.5.53.62025-09-03
CVE-2023-21483 [MEDIUM] CVE-2023-21483: Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacke
Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.
nvd
1 / 2Next →