CVE Vulnerabilities

CVE-2023-42580

Published: Dec 05, 2023 | Modified: Dec 12, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.

Affected Software

Name Vendor Start Version End Version
Galaxy_store Samsung * 4.5.64.4 (excluding)

References