CVE-2021-25354Improper Authorization in Mobile Samsung Internet

Severity
5.3MEDIUMNVD
CNA3.3
EPSS
0.2%
top 63.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 24

Description

Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4

Affected Packages2 packages

NVDsamsung/internet< 13.2.1.46
CVEListV5samsung_mobile/samsung_internetunspecified13.2.1.46

🔴Vulnerability Details

2
GHSA
GHSA-j4r4-w82p-8vjq: Improper input check in Samsung Internet prior to version 132022-05-24
CVEList
CVE-2021-25354: Improper input check in Samsung Internet prior to version 132021-03-25
CVE-2021-25354 — Improper Authorization | cvebase