Improper Authorization Vulnerability in Galaxy Store by Samsung
CVE-2022-22288

7.5HIGH

Key Information:

Vendor
Samsung
Vendor
CVE Published:
10 January 2022

Summary

An improper authorization vulnerability exists in the Galaxy Store prior to version 4.5.36.5, which could allow remote attackers to install applications without appropriate authorization. This flaw exposes users to potential security risks by enabling unauthorized access to app installation features, leading to possible exploitation.

Affected Version(s)

Galaxy Store - < 4.5.36.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.