PT-2022-3435 · Samsung · Galaxy Store

Ken Gannon

·

Published

2022-04-11

·

Updated

2023-06-28

·

CVE-2022-28776

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Galaxy Store versions prior to 4.5.36.4
Description The issue is related to improper access control in the Galaxy Store, allowing an attacker to install applications without user interaction. This can be exploited by manipulating the intent received by the Galaxy App Store, forcing it to automatically install other applications onto the victim's device without consent.
Recommendations For Galaxy Store versions prior to 4.5.36.4, update to version 4.5.36.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Galaxy Store until the update is applied.

Fix

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2022-04213
CVE-2022-28776

Affected Products

Galaxy Store