CVE-2023-21434: Samsung Galaxy Store

Medium severity, CVSS 6.1. EPSS: 12.9% chance of exploitation in the next 30 days.

Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.

Affected products

  • Samsung Galaxy Store: before 4.5.49.8 (fixed in 4.5.49.8)

Published 2023-02-09. Last modified 2026-06-17.