Samsung / Internet
29 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-21036 | Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. | MEDIUM | 6.3 | Jun 5, 2026 |
| CVE-2025-58485 | Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script. | MEDIUM | 5.5 | Dec 2, 2025 |
| CVE-2025-20995 | Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local atta… | HIGH | 7.1 | Jun 4, 2025 |
| CVE-2025-20994 | Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local… | HIGH | 7.1 | Jun 4, 2025 |
| CVE-2025-32407 | Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attack… | MEDIUM | 5.9 | May 16, 2025 |
| CVE-2024-34671 | Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive informa… | MEDIUM | 5.5 | Oct 8, 2024 |
| CVE-2024-20869 | Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies. | MEDIUM | 5.5 | May 7, 2024 |
| CVE-2024-20838 | Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code. | HIGH | 7.8 | Mar 5, 2024 |
| CVE-2024-20837 | Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission t… | MEDIUM | 5.3 | Mar 5, 2024 |
| CVE-2024-20829 | Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper in… | MEDIUM | 5.4 | Mar 5, 2024 |
| CVE-2024-20828 | Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode… | MEDIUM | 4.6 | Feb 6, 2024 |
| CVE-2023-30704 | Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without use… | MEDIUM | 4.6 | Aug 10, 2023 |
| CVE-2023-30674 | Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie. | MEDIUM | 6.5 | Jul 6, 2023 |
| CVE-2022-39873 | Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user auth… | MEDIUM | 4.6 | Oct 7, 2022 |
| CVE-2022-30740 | Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers. | MEDIUM | 4.3 | Jun 7, 2022 |
| CVE-2022-30738 | Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script. | MEDIUM | 4.3 | Jun 7, 2022 |
| CVE-2022-27839 | Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credenti… | MEDIUM | 4.0 | Apr 11, 2022 |
| CVE-2022-22290 | Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page. | MEDIUM | 6.5 | Jan 14, 2022 |
| CVE-2022-22284 | Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication | MEDIUM | 5.7 | Jan 7, 2022 |
| CVE-2021-25521 | Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet. | MEDIUM | 4.0 | Dec 8, 2021 |
| CVE-2021-25520 | Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to e… | MEDIUM | 6.1 | Dec 8, 2021 |
| CVE-2021-25466 | Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Acco… | MEDIUM | 6.5 | Sep 9, 2021 |
| CVE-2021-25445 | Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet. | MEDIUM | 5.3 | Aug 5, 2021 |
| CVE-2021-25400 | Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action. | HIGH | 7.8 | Jun 11, 2021 |
| CVE-2021-25419 | Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phisi… | MEDIUM | 6.5 | Jun 11, 2021 |
Showing 1 to 25 of 29 CVEs