CVE Published: 26/05/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: Samsung Mobile |
Vendor: Samsung Mobile |
Product: Galaxy Store Status : PUBLISHED
CVE-2023-21515 Description
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H