{"id":466955,"date":"2022-11-01T10:39:08","date_gmt":"2022-11-01T08:39:08","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=466955"},"modified":"2022-11-01T10:41:38","modified_gmt":"2022-11-01T08:41:38","slug":"samsung-fixes-galaxy-store-security-bug","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/466955-samsung-fixes-galaxy-store-security-bug.html","title":{"rendered":"Samsung fixes Galaxy Store security bug"},"content":{"rendered":"<p>Samsung has patched a security flaw relating to the Galaxy Store app that attackers could exploit to execute remote code on affected smartphones, The Hacker News <strong><a href=\"https:\/\/thehackernews.com\/2022\/10\/samsung-galaxy-store-bug-couldve-let.html\" target=\"_blank\" rel=\"noopener\">reports<\/a><\/strong>.<\/p>\n<p>The vulnerability involves a cross-site scripting (XSS) flaw related to deep link handling. Only Galaxy Store version 4.5.32.4 is affected.<\/p>\n<p>XSS attacks can let attackers introduce and execute malicious JavaScript code when a user visits a website through a browser or another application.<\/p>\n<p>SSD Secure Disclosure released an <strong><a href=\"https:\/\/ssd-disclosure.com\/ssd-advisory-galaxy-store-applications-installation-launching-without-user-interaction\/\" target=\"_blank\" rel=\"noopener\">advisory<\/a><\/strong> on 26 October 2022, explaining how the Galaxy Store&#8217;s failure to check deep links can result in an attack.<\/p>\n<p>&#8220;Here, by not checking the deep link securely, when a user accesses a link from a website containing the deep link, the attacker can execute JS code in the webview context of the Galaxy Store application,&#8221; it said.<\/p>\n<p>The Galaxy Store vulnerability relates to how deep links are configured for Samsung&#8217;s Marketing and Content Service (MCS).<\/p>\n<p>In a scenario where arbitrary code is injected into the MCS website, malicious actors could execute the code to download and install apps laced with malware when a user visits the link.<\/p>\n<p>&#8220;To be able to successfully exploit the victim&#8217;s server, it is necessary to have HTTPS and CORS bypass of Chrome,&#8221; SSD Secure Disclosure added.<\/p>\n<hr \/>\n<h2 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/466767-actively-exploited-windows-mark-of-the-web-flaw-gets-unofficial-patch.html\" rel=\"bookmark\">Actively exploited Windows mark-of-the-web flaw gets unofficial patch<\/a><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>The now-patched vulnerability could have provided an angle for attackers to remotely execute malicious code and download and install apps laced with malware.<\/p>\n","protected":false},"author":341076,"featured_media":466957,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[32118,82395,82045,645],"class_list":["post-466955","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cross-site-scripting-xss-attack","tag-galaxy-store","tag-remote-code-execution","tag-samsung"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/466955"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=466955"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/466955\/revisions"}],"predecessor-version":[{"id":466979,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/466955\/revisions\/466979"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/466957"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=466955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=466955"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=466955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}