Samsung Internet vulnerabilities

28 known vulnerabilities affecting samsung/internet.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM20LOW3

Vulnerabilities

Page 2 of 2
CVE-2021-25466MEDIUMCVSS 5.9fixed in 15.0.2.472021-09-09
CVE-2021-25466 [MEDIUM] CWE-287 CVE-2021-25466: Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
nvd
CVE-2021-25445MEDIUMCVSS 5.3fixed in 14.22021-08-05
CVE-2021-25445 [MEDIUM] CWE-287 CVE-2021-25445: Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted appli Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet.
nvd
CVE-2021-25418HIGHCVSS 7.8fixed in 14.0.1.622021-06-11
CVE-2021-25418 [HIGH] CWE-269 CVE-2021-25418: Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows un Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.
nvd
CVE-2021-25400HIGHCVSS 7.8fixed in 14.0.1.202021-06-11
CVE-2021-25400 [HIGH] CWE-926 CVE-2021-25400: Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to e Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
nvd
CVE-2021-25419MEDIUMCVSS 6.5fixed in 14.0.1.622021-06-11
CVE-2021-25419 [MEDIUM] CWE-703 CVE-2021-25419: Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 al Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link.
nvd
CVE-2021-25354MEDIUMCVSS 5.3fixed in 13.2.1.462021-03-25
CVE-2021-25354 [MEDIUM] CWE-285 CVE-2021-25354: Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-e Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.
nvd
CVE-2021-25366LOWCVSS 2.9fixed in 13.2.1.702021-03-25
CVE-2021-25366 [LOW] CWE-703 CVE-2021-25366: Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate a Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.
nvd
CVE-2021-25348LOWCVSS 2.4fixed in 13.0.1.602021-03-04
CVE-2021-25348 [LOW] CWE-703 CVE-2021-25348: Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to file Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.
nvd