CVE Tools

Galaxy Store

31 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Galaxy Store, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.

Galaxy Store CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Galaxy Store CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-030
2025-041
2025-050
2025-060
2025-070
2025-080
2025-091
2025-100
2025-110
2025-121
2026-011
2026-020
2026-033
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 31 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High1239%
  • Medium1858%
  • Low13%

Latest CVEs

The 15 most recently published vulnerabilities affecting Galaxy Store.

  1. CVE-2026-21002Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.5.5
  2. CVE-2026-21001Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.5.5
  3. CVE-2026-21000Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.5.5
  4. CVE-2026-20976Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.7.8
  5. CVE-2025-58483Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store.5.9
  6. CVE-2023-21483Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.6.4
  7. CVE-2025-20951Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.5.1
  8. CVE-2025-20895Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.3.2
  9. CVE-2024-34601Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.5.9
  10. CVE-2024-20870Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.5.1
  11. CVE-2024-20825Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.5.5
  12. CVE-2024-20824Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.5.5
  13. CVE-2024-20823Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.5.5
  14. CVE-2024-20822Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.5.5
  15. CVE-2023-42581Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store