Search

Samsung's Latest Galaxy Store Update Fixes Vulnerability That Let Hackers Install Apps Without Informing Users

Samsung Galaxy store has been detected to have two vulnerabilities that let hackers install applications without informing users.

Advertisement
Highlights
  • Samsung rolls out Galaxy Store app updated version 4.5.49.8
  • The Update is released for handsets running Android 12
  • Samsung handsets running Android 13 are not affected
Samsung's Latest Galaxy Store Update Fixes Vulnerability That Let Hackers Install Apps Without Informing Users

The Galaxy Store vulnerabilities let hackers execute JavaScript on a target device

Photo Credit: Samsung

Samsung has released a Galaxy Store app update to fix vulnerabilities that could potentially allow malicious sources to install apps without a user's permission. Two vulnerabilities were reportedly detected on the Galaxy Store by a research team. These vulnerabilities have only been affecting handsets running Android 12 or lower. Android 13 users are not affected by this. Users can open the Galaxy Store on their phones, and download and install the latest Galaxy Store app version 4.5.49.8.

According to a report by NCC research team, the Galaxy Store app, which comes pre-installed on Galaxy smartphones, has been detected with two security vulnerabilities CVE-2023-21433 and CVE-2023-21434. The vulnerabilities allow hackers to install malicious apps on vulnerable Samsung handsets without the owner's permission as well as execute JavaScript by launching a Web page.

The report shares that a pre-installed rouge application or malicious hyperlink in Google Chrome on Galaxy phones running Android 12 bypass Samsung's URL filter and install any application available on the Galaxy Store. Further, they even launch a webview controlled by the attacker. Notably, these vulnerabilities have only been affecting Galaxy phones running Android 12, while Android 13 supported phones are safe.

Hence, to fix these bugs, Samsung has rolled out an updated version of the Galaxy Store app (version 4.5.49.8). Users can head to the Galaxy Store settings on their phones, and download and install the latest version of the app. Samsung has rated the abovementioned vulnerabilities as Moderate risks.

The Galaxy Store was reported to distribute malicious apps asking for excessive permissions, including access to the phone, earlier as well. In December 2021, different Showbox movie piracy app clones available on Galaxy Store were spotted infecting devices with malware. Tipster Max Weinbach reported a similar type of issue that was previously discovered on Huawei phones. He shared that the Showbox-based app installations from the Galaxy store were stopped by Google's Play Protect warning. At least five of the Showbox-based apps were infected with dangerous malware. 

 


The iQoo 11 is currently the most powerful Android phone you can buy in India. Should you buy it right away? We discuss this and more on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Poco M7 Pro Review: Pro Value
  1. Étoile OTT Release Date: When and Where to Watch it Online?
  2. Mr Housekeeping Now Streaming on Aha Tamil: Everything You Need to Know
  3. Guilty Gear Strive: Dual Rulers OTT Release Date: When and Where to Watch it Online?
  4. AMoRE Experiment Sets New Benchmark in Neutrinoless Double Beta Decay Research
  5. Did Black Hole Radiation Shape the Universe?
  6. Aghathiyaa Tamil Fantasy Thriller Now Streaming on Sun NXT
  7. Google Pixel 9a Sale Date Revealed; to Be Available for Purchase in India Starting April 16
  8. Artemis II Orion Service Module Secured for Launch at Kennedy Space Center
  9. Zakir Khan’s Delulu Express Stand-Up Special Now Streaming on Prime Video
  10. NASA to Launch Three Rockets in Alaska to Study Auroral Substorms’ Impact
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »