Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.
https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=10