CVE-2023-42581: Samsung Galaxy Store

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.

Affected products

  • Samsung Galaxy Store: before 4.5.64.4 (fixed in 4.5.64.4)

Published 2023-12-05. Last modified 2026-06-17.