Vulnerability in InstantPlay Allows Unauthorized APK Installation from Galaxy Store

Vulnerability in InstantPlay Allows Unauthorized APK Installation from Galaxy Store

CVE-2023-21515 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.

Learn more about our Api Penetration Testing.