Improper Permission Handling in Samsung Internet on Non-Samsung Devices
CVE-2025-20995

4.9MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
4 June 2025

What is CVE-2025-20995?

A vulnerability exists in Samsung Internet due to improper handling of insufficient permissions in ClientProvider on non-Samsung devices. This flaw allows local attackers to read and write arbitrary files, potentially leading to unauthorized data access and manipulation. Users are encouraged to update to version 28.0.0.59 or later to mitigate this risk.

Affected Version(s)

Samsung Internet 28.0.0.59

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.