CVE-2023-21514: Samsung Galaxy Store

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.

Affected products

  • Samsung Galaxy Store: before 4.5.49.8 (fixed in 4.5.49.8)

Published 2023-05-26. Last modified 2026-06-17.