Samsung
Samsung Galaxy Store: vulnerabilidades y CVE
Samsung Galaxy Store tiene 31 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses5
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21002 | Media (5.9) | 0.07% | — | 16 mar 2026 | Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application. |
| CVE-2026-21001 | Media (5.9) | 0.12% | — | 16 mar 2026 | Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege. |
| CVE-2026-21000 | Alta (7) | 0.13% | — | 16 mar 2026 | Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege. |
| CVE-2026-20976 | Media (5.1) | 0.16% | — | 9 ene 2026 | Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script. |
| CVE-2025-58483 | Baja (3.3) | 0.10% | — | 2 dic 2025 | Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store. |
| CVE-2023-21483 | Media (5.5) | 0.10% | — | 3 sept 2025 | Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service. |
| CVE-2025-20951 | Media (5.5) | 0.14% | — | 8 abr 2025 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store. |
| CVE-2025-20895 | Media (4.6) | 0.20% | — | 4 feb 2025 | Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard. |
| CVE-2024-34601 | Media (5.3) | 0.13% | — | 2 jul 2024 | Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore. |
| CVE-2024-20870 | Media (5.5) | 0.14% | — | 7 may 2024 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store. |
| CVE-2024-20825 | Media (5.5) | 0.17% | — | 6 feb 2024 | Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. |
| CVE-2024-20824 | Media (5.5) | 0.17% | — | 6 feb 2024 | Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. |
| CVE-2024-20823 | Media (5.5) | 0.17% | — | 6 feb 2024 | Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. |
| CVE-2024-20822 | Media (5.5) | 0.17% | — | 6 feb 2024 | Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. |
| CVE-2023-42581 | Alta (7.5) | 1.2% | — | 5 dic 2023 | Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data. |
| CVE-2023-42580 | Crítica (9.8) | 0.97% | — | 5 dic 2023 | Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store. |
| CVE-2023-30705 | Media (5.5) | 0.15% | — | 10 ago 2023 | Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission. |
| CVE-2023-21516 | Crítica (9.6) | 0.55% | — | 26 may 2023 | XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. |
| CVE-2023-21515 | Alta (8.8) | 0.52% | — | 26 may 2023 | InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. |
| CVE-2023-21514 | Alta (8.8) | 0.52% | — | 26 may 2023 | Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. |
| CVE-2023-21434 | Media (6.1) | 13% | — | 9 feb 2023 | Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page. |
| CVE-2023-21433 | Alta (7.8) | 3.7% | — | 9 feb 2023 | Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store. |
| CVE-2022-33710 | Alta (7.8) | 0.21% | — | 12 jul 2022 | Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege. |
| CVE-2022-33709 | Alta (7.8) | 0.21% | — | 12 jul 2022 | Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege. |
| CVE-2022-33708 | Alta (7.8) | 0.21% | — | 12 jul 2022 | Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege. |
| CVE-2022-28791 | Media (5.5) | 0.22% | — | 3 may 2022 | Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to… |
| CVE-2022-28776 | Alta (7.8) | 0.27% | — | 11 abr 2022 | Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions. |
| CVE-2022-28544 | Media (5.5) | 0.90% | — | 11 abr 2022 | Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store. |
| CVE-2022-28542 | Media (5.5) | 0.27% | — | 11 abr 2022 | Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission. |
| CVE-2022-22288 | Alta (7.5) | 0.92% | — | 10 ene 2022 | Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.