» » Samsung Galaxy Store Flaws Can Lead to Unwanted App Installations, Code Execution

Samsung Galaxy Store Flaws Can Lead to Unwanted App Installations, Code Execution

Samsung Galaxy Store Flaws Can Lead to Unwanted App Installations, Code Execution

House › Cellular Safety

Samsung Galaxy Retailer Flaws Can Result in Undesirable App Installations, Code Execution

By Ionut Arghire on January 23, 2023

Tweet

Cybersecurity agency NCC Group has shared particulars on two vulnerabilities in Samsung’s Galaxy Retailer that may very well be exploited to put in purposes or execute JavaScript code by launching an online web page.

Another app market, the Galaxy Retailer comes pre-installed on Samsung’s Android gadgets and can be utilized alongside Google Play to obtain and set up software program.

Tracked as CVE-2023-21433, the primary of the vulnerabilities that NCC Group has recognized might permit rogue purposes on a tool to obtain and set up further software program from the Galaxy Retailer, with out the person’s data.

The problem is described as an improper entry management flaw, the place the app retailer contained an exported exercise that failed to securely deal with incoming intents. The bug, NCC explains, solely impacted gadgets working Android 12 and older.

The second vulnerability, CVE-2023-21434, is described as an improper enter validation difficulty that would permit an area attacker to execute JavaScript code by launching an online web page.

“It was discovered {that a} webview inside the Galaxy App Retailer contained a filter which restricted which domains that webview might browse to. Nevertheless, the filter was not correctly configured, which might permit the webview to browse to an attacker-controlled area,” NCC Group explains.

The vulnerability will be exploited by tapping a malicious URL in Chrome or a pre-installed rogue utility, which might bypass present URL filtering.

The cybersecurity agency has revealed proof-of-concept (PoC) code for each these vulnerabilities.

The safety defects have been reported to Samsung in November and December 2022. Each points have been addressed in Galaxy Retailer model 4.5.49.8.

House owners of Samsung gadgets working Android 12 or under are suggested to replace to the most recent model of Galaxy Retailer as quickly as doable.

Associated: VMware Warns of Exploit for Latest NSX-V Vulnerability

Associated: CISA Warns of Assaults Exploiting Latest Atlassian Bitbucket Vulnerability

Associated: Owl Labs Patches Extreme Vulnerability in Video Conferencing Units

Get the Every day Briefing

 
 
 

  • Most Latest
  • Most Learn
  • Apple Patches WebKit Code Execution Flaws
  • Thoma Bravo to Purchase Magnet Forensics in Billion-Greenback Deal
  • Microsoft Invests Billions in ChatGPT-maker OpenAI
  • Samsung Galaxy Retailer Flaws Can Result in Undesirable App Installations, Code Execution
  • NSA Publishes Safety Steerage for Organizations Transitioning to IPv6
  • Majority of GAO’s Cybersecurity Suggestions Not Applied by Federal Companies
  • Corporations Impacted by Latest Mailchimp Breach Begin Notifying Clients
  • Mississippi Creates New Cyber Unit, Names 1st Director
  • FBI Chief Says He is ‘Deeply involved’ by China’s AI Program
  • In-the-Wild Exploitation of Latest ManageEngine Vulnerability Commences

In search of Malware in All of the Improper Locations?

First Step For The Web’s subsequent 25 years: Including Safety to the DNS

Tattle Story: What Your Pc Says About You

Be in a Place to Act By way of Cyber Situational Consciousness

Report Exhibits Closely Regulated Industries Letting Social Networking Apps Run Rampant

2010, A Nice 12 months To Be a Scammer.

Do not Let DNS be Your Single Level of Failure

Easy methods to Establish Malware in a Blink

Defining and Debating Cyber Warfare

The 5 A’s that Make Cybercrime so Enticing

Easy methods to Defend Towards DDoS Assaults

Safety Budgets Not in Line with Threats

Anycast – Three Causes Why Your DNS Community Ought to Use It

The Evolution of the Prolonged Enterprise: Safety Methods for Ahead Pondering Organizations

Utilizing DNS Throughout the Prolonged Enterprise: It’s Dangerous Enterprise

SecurityWeek Podcast

author-Orbit Brain
Orbit Brain
Orbit Brain is the senior science writer and technology expert. Our aim provides the best information about technology and web development designing SEO graphics designing video animation tutorials and how to use software easy ways
and much more. Like Best Service Latest Technology, Information Technology, Personal Tech Blogs, Technology Blog Topics, Technology Blogs For Students, Futurism Blog.

Cyber Security News Related Articles