Samsung Galaxy Store security flaws may allow hackers to install apps and more, here’s how

The Galaxy Store is Samsung’s app store that comes pre-installed on the company’s devices. A new security flaw in the Galaxy Store is reportedly making Samsung’s devices vulnerable and is leaving users at potential risk. Samsung users have been advised to update the Galaxy Store on their Samsung smartphone or tablet immediately, to avoid any attack. According to a report by 9To5Google, cybersecurity researchers at NCC Group have revealed two significant security vulnerabilities affecting the Galaxy Store app store.
These security flaws are being shipped on Samsung’s Android smartphones and tablets. The South Korea-based tech giant has fixed both vulnerabilities, but users will need to update the store to apply these fixes. Samsung has already rolled out the Galaxy Store version 4.5.49.8 update to patch both of these security issues.
Samsung Galaxy Store security flaw: What are they
The first vulnerability is named CVE-2023-21433 and it is caused by “improper access control” in the Galaxy Store. This flaw allows attackers to install apps on a user’s device without their permission. For hackers to install the app, it has to be available on the Galaxy Store in the first place. However, the issue only affects Samsung Galaxy devices running Android 12 and older.

Devices that have been upgraded to Android 13 are immune to this particular issue. The impact of this vulnerability is relatively minor as it can only install apps from the app store. However, this is not a safe practice and used should fix the issue immediately.
Another vulnerability is called CVE-2023-21434 and it also had the potential to cause trouble. This bug caused Galaxy Store’s webview filter to configure improperly. This allowed users to access risky domains as long as they had similar elements to an approved URL. The primary concern with his flaw was the JavaScript attacks, which could have been loaded.
Also Watch:

Samsung AX46 Air Purifier: Bigger but is it better?

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechNewsBoy.com is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.