Samsung Galaxy Store App Found Vulnerable to Sneaky App Installs and Fraud

0
278
Samsung Galaxy Store App Found Vulnerable to Sneaky App Installs and Fraud


Jan 23, 2023Ravie LakshmananMobile Hacking / App Security

Samsung Galaxy Store App Found Vulnerable to Sneaky App Installs and Fraud

Two safety flaws have been disclosed in Samsung’s Galaxy Store app for Android that might be exploited by an area attacker to stealthily set up arbitrary apps or direct potential victims to fraudulent touchdown pages on the net.

The points, tracked as CVE-2023-21433 and CVE-2023-21434, have been found by NCC Group and notified to the South Korean chaebol in November and December 2022. Samsung labeled the bugs as average threat and launched fixes in model 4.5.49.8 shipped earlier this month.

Samsung Galaxy Store, beforehand often called Samsung Apps and Galaxy Apps, is a devoted app retailer used for Android units manufactured by Samsung. It was launched in September 2009.

The first of the 2 vulnerabilities is CVE-2023-21433, which may allow an already put in rogue Android app on a Samsung machine to put in any software out there on the Galaxy Store.

Samsung described it as a case of improper entry management that it stated has been patched with correct permissions to forestall unauthorized entry.

It’s price noting right here that the shortcoming solely impacts Samsung units which can be working Android 12 and earlier than, and doesn’t have an effect on these which can be on the most recent model (Android 13).

The second vulnerability, CVE-2023-21434, pertains to an occasion of improper enter validation occurring when limiting the listing of domains that might be launched as a WebView from throughout the app, successfully enabling a risk actor to bypass the filter and browse to a website beneath their management.

“Either tapping a malicious hyperlink in Google Chrome or a pre-installed rogue software on a Samsung machine can bypass Samsung’s URL filter and launch a webview to an attacker managed area,” NCC Group researcher Ken Gannon stated.

The replace comes as Samsung rolled out safety updates for the month of January 2023 to remediate a number of flaws, a few of which might be exploited to switch service community parameters, management BLE promoting with out permission, and obtain arbitrary code execution.

Found this text attention-grabbing? Follow us on Twitter and LinkedIn to learn extra unique content material we publish.

LEAVE A REPLY

Please enter your comment!
Please enter your name here