Improper Component Protection in Samsung Internet Affects Samsung Devices
CVE-2021-25418

7.8HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
11 June 2021

What is CVE-2021-25418?

An improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 permits untrusted applications to execute arbitrary activities. This issue could potentially compromise the security of users by allowing malicious apps to perform unauthorized actions within the browser, leading to data breaches or further exploitation of the device. It highlights the importance of maintaining updated software to mitigate security risks.

Affected Version(s)

Samsung Internet < 14.0.1.62

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.