A researcher disclosed an exploit chain targeting the Samsung Galaxy Store on the Samsung S22 that used a single malicious click to trigger app installation and launch. The attack abused Galaxy Store deeplink handling and a server-side open redirect on us.mcsvc.samsung.com, allowing a trusted internal WebView to be redirected to an apps.samsung.com deeplink with parameters such as directInstall=true and directOpen=true. That flow caused the Galaxy Store to automatically install and immediately open a Samsung application without additional user interaction.
The technique built on earlier 2021 research into Galaxy Store internals, where an XSS flaw in redirect.html and access to the Galaxy Store JavaScript interface had enabled code execution in an internal WebView. After Samsung fixed the XSS issue, the researcher found that a new open-redirect condition remained exploitable and reported that Samsung issued multiple server-side patches before fully resolving the problem on December 2, 2022, with bypasses identified during the remediation process. Users were advised to update the Galaxy Store application to the latest available version.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
STAR Labs publicly disclosed the exploitation details, contrasted the 2021 and 2022 chains, and advised users to update the Galaxy Store application to the latest version.
According to the write-up, Samsung finally resolved the server-side open-redirect vulnerability after several patch attempts.
Samsung repeatedly patched and re-patched the server-side open-redirect issue, but the researcher found bypasses during the remediation period.
The Samsung Galaxy Store one-click/open-redirect exploit chain was developed and presented in connection with Pwn2Own Toronto 2022, demonstrating compromise of a Samsung S22 device.
After the XSS fix, the researcher identified a new server-side open redirect on us.mcsvc.samsung.com and chained it with Galaxy Store deeplink handling to trigger automatic app installation and launch on a Samsung S22 with one click.
Samsung patched the earlier XSS vulnerability in redirect.html, closing the original 2021 exploit path described by the researcher.
Prior Galaxy Store research in 2021 found that a deeplink into Samsung's McsWebViewActivity combined with an XSS flaw in redirect.html could execute JavaScript in an internal WebView and access the GalaxyStore JavaScript interface.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.