Insufficient Permission Vulnerability in Samsung Internet Browser on Non-Samsung Devices
CVE-2025-20994
4.5MEDIUM
What is CVE-2025-20994?
An improper handling of insufficient permissions vulnerability exists in the SyncClientProvider of Samsung Internet, impacting non-Samsung devices running versions prior to 28.0.0.59. This flaw potentially enables local attackers to gain unauthorized access to read and write arbitrary files, posing a risk to user data and system integrity.
Affected Version(s)
Samsung Internet 28.0.0.59
References
CVSS V3.1
Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved