CVE-2023-42580

HIGH

Samsung Galaxy Store < 4.5.64.4 - Unauthenticated Arbitrary APK Installation via MCSLaunch Deeplink

Title source: llm
STIX 2.1

Description

Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0037
EPSS Percentile 58.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
samsung/galaxy_store < 4.5.64.4
Published Dec 05, 2023
Tracked Since Feb 18, 2026