Samsung Internet vulnerabilities
29 known vulnerabilities affecting samsung/internet.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM21LOW3
Vulnerabilities
Page 1 of 2
CVE-2024-20838P3HIGHCVSS 7.8fixed in 24.0.3.22024-03-05
CVE-2024-20838 [HIGH] CVE-2024-20838: Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attacke
Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code.
nvd
CVE-2021-25418P3HIGHCVSS 7.8fixed in 14.0.1.622021-06-11
CVE-2021-25418 [HIGH] CWE-269 CVE-2021-25418: Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows un
Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.
nvd
CVE-2021-25400P3HIGHCVSS 7.8fixed in 14.0.1.202021-06-11
CVE-2021-25400 [HIGH] CWE-926 CVE-2021-25400: Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to e
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
nvd
CVE-2025-20995P3HIGHCVSS 7.1fixed in 28.0.0.592025-06-04
CVE-2025-20995 [HIGH] CVE-2025-20995: Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-
Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and write arbitrary files.
nvd
CVE-2025-20994P4HIGHCVSS 7.1fixed in 28.0.0.592025-06-04
CVE-2025-20994 [HIGH] CVE-2025-20994: Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on
Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to access read and write arbitrary files.
nvd
CVE-2023-30674P4MEDIUMCVSS 6.5fixed in 21.0.0.412023-07-06
CVE-2023-30674 [MEDIUM] CVE-2023-30674: Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass Same
Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie.
nvd
CVE-2025-32407P4MEDIUMCVSS 5.9v5.0.92025-05-16
CVE-2025-32407 [MEDIUM] CWE-295 CVE-2025-32407: Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not
Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user. This is a critical misconfiguration in the way the browser validates the identity of the server. It negates the use of HTTPS as a se
nvd
CVE-2021-25419P4MEDIUMCVSS 6.5fixed in 14.0.1.622021-06-11
CVE-2021-25419 [MEDIUM] CWE-703 CVE-2021-25419: Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 al
Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link.
nvd
CVE-2022-22290P4MEDIUMCVSS 6.5fixed in 16.0.6.232022-01-14
CVE-2022-22290 [MEDIUM] CWE-703 CVE-2022-22290: Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to
Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.
nvd
CVE-2021-25466P4MEDIUMCVSS 5.9fixed in 15.0.2.472021-09-09
CVE-2021-25466 [MEDIUM] CWE-287 CVE-2021-25466: Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
nvd
CVE-2022-22284P4MEDIUMCVSS 5.5fixed in 16.0.2.192022-01-10
CVE-2022-22284 [MEDIUM] CWE-287 CVE-2022-22284: Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to byp
Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication
nvd
CVE-2024-20829P4MEDIUMCVSS 5.3v24.02024-03-05
CVE-2024-20829 [MEDIUM] CVE-2024-20829: Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allow
Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.
nvd
CVE-2021-25445P4MEDIUMCVSS 5.3fixed in 14.22021-08-05
CVE-2021-25445 [MEDIUM] CWE-287 CVE-2021-25445: Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted appli
Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet.
nvd
CVE-2021-25520P4MEDIUMCVSS 6.1fixed in 16.0.22021-12-08
CVE-2021-25520 [MEDIUM] CWE-20 CVE-2021-25520: Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to
Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.
nvd
CVE-2025-58485P4MEDIUMCVSS 5.5fixed in 29.0.0.482025-12-02
CVE-2025-58485 [MEDIUM] CVE-2025-58485: Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to i
Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script.
nvd
CVE-2026-21036P4MEDIUMCVSS 5.5fixed in 30.0.0.392026-06-05
CVE-2026-21036 [MEDIUM] CWE-863 CVE-2026-21036: Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to acce
Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.
nvd
CVE-2024-20869P4MEDIUMCVSS 5.5fixed in 25.0.0.412024-05-07
CVE-2024-20869 [MEDIUM] CVE-2024-20869: Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows lo
Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.
nvd
CVE-2024-20837P4MEDIUMCVSS 5.3fixed in 24.0.0.412024-03-05
CVE-2024-20837 [MEDIUM] CVE-2024-20837: Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to ver
Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.
nvd
CVE-2024-34671P4MEDIUMCVSS 5.5fixed in 26.0.3.12024-10-08
CVE-2024-34671 [MEDIUM] CVE-2024-34671: Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to versi
Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-20828P4MEDIUMCVSS 4.6fixed in 24.02024-02-06
CVE-2024-20828 [MEDIUM] CWE-863 CVE-2024-20828: Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows p
Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.
nvd
1 / 2Next →