Improper Authentication in Samsung Internet Browser
CVE-2022-22284

5.7MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
10 January 2022

What is CVE-2022-22284?

An improper authentication vulnerability exists in Samsung Internet prior to version 16.0.2.19, enabling attackers to bypass password protection for the secret mode. This flaw could allow unauthorized access to sensitive information stored within the browser’s secret mode, posing risks to user privacy and security.

Affected Version(s)

Samsung Internet - < 16.0.2.19

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.