Insufficient Permission Vulnerability in Samsung Internet Browser on Non-Samsung Devices
CVE-2025-20994

4.5MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
4 June 2025

What is CVE-2025-20994?

An improper handling of insufficient permissions vulnerability exists in the SyncClientProvider of Samsung Internet, impacting non-Samsung devices running versions prior to 28.0.0.59. This flaw potentially enables local attackers to gain unauthorized access to read and write arbitrary files, posing a risk to user data and system integrity.

Affected Version(s)

Samsung Internet 28.0.0.59

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.