Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Can install arbitrary application / boot to malicious website, Samsung Galaxy Store exposed two security vulnerabilities

Shulou Source: shulou.com Published: 2023-11-24 14:12:00 10月02日 Update

CTOnews.com, January 21, NCC Group researchers found that there are two CVE vulnerabilities in Samsung's official app mall. Attackers can use these two vulnerabilities to install arbitrary applications without the user's knowledge, or direct the victim to a malicious Web address.

NCC Group researchers identified these two vulnerabilities between November 23 and December 3, 2022, and Samsung fixed them in Galaxy Store version 4.5.49.8. NCC Group researcher Mishaal Rahman disclosed these two vulnerabilities today.

CTOnews.com learned that Samsung devices that have been upgraded to Android 13 / OneUI 5.0 will not be affected, and Samsung devices running Android 12 and earlier will not be affected after upgrading to the new version.

NCC Group found that a webview in Galaxy App Store contains a filter that limits the fields that webview can browse. This will allow webview to browse to the domain controlled by the attacker, regardless of whether the developer has configured it correctly.

Tags: Two vulnerabilities Samsung personnel researchers research apps attackers versions devices filters Android upgrades impact attacks browsing malicious victims malls addresses Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Information Linux MariaDB MySQL Microsoft