Same Origin Policy Bypass in Samsung Internet Browser
CVE-2017-17692
Key Information:
- Vendor
- Samsung
- Status
- Vendor
- CVE Published:
- 21 December 2017
Badges
Summary
The Samsung Internet Browser version 5.4.02.3 contains a vulnerability that allows remote attackers to bypass the Same Origin Policy. By exploiting this flaw, attackers can execute crafted JavaScript code which can redirect to a child tab and manipulate the innerHTML property, potentially leading to unauthorized access to sensitive information. This vulnerability compromises the security of users by undermining a fundamental web security mechanism.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
62% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved