Domain Spoofing in Samsung Internet Browser
CVE-2022-22290
6.5MEDIUM
What is CVE-2022-22290?
The Samsung Internet browser is affected by a vulnerability that allows attackers to exploit an incorrect download source UI. This flaw enables domain spoofing via a specially crafted HTML page, which can mislead users into believing they are interacting with legitimate content. As a result, attackers can potentially harvest sensitive information or execute malicious actions unbeknownst to the user. Users are advised to update to version 16.0.6.23 or later to mitigate this security risk.
Affected Version(s)
Samsung Internet - < 16.0.6.23