Samsung
Samsung Internet: vulnerabilidades y CVE
Samsung Internet tiene 29 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21036 | Media (6.3) | 0.09% | — | 5 jun 2026 | Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. |
| CVE-2025-58485 | Media (5.5) | 0.12% | — | 2 dic 2025 | Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script. |
| CVE-2025-20995 | Alta (7.1) | 0.12% | — | 4 jun 2025 | Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and write arbitrary files. |
| CVE-2025-20994 | Alta (7.1) | 0.11% | — | 4 jun 2025 | Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to access read and write arbitrary files. |
| CVE-2025-32407 | Media (5.9) | 0.29% | — | 16 may 2025 | Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user.… |
| CVE-2024-34671 | Media (5.5) | 0.16% | — | 8 oct 2024 | Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this… |
| CVE-2024-20869 | Media (5.5) | 0.15% | — | 7 may 2024 | Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies. |
| CVE-2024-20838 | Alta (7.8) | 0.18% | — | 5 mar 2024 | Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code. |
| CVE-2024-20837 | Media (5.3) | 0.15% | — | 5 mar 2024 | Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction. |
| CVE-2024-20829 | Media (5.3) | 0.35% | — | 5 mar 2024 | Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction. |
| CVE-2024-20828 | Media (4.6) | 0.24% | — | 6 feb 2024 | Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication. |
| CVE-2023-30704 | Media (4.6) | 0.23% | — | 10 ago 2023 | Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication. |
| CVE-2023-30674 | Media (6.5) | 0.58% | — | 6 jul 2023 | Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie. |
| CVE-2022-39873 | Media (4.6) | 0.25% | — | 7 oct 2022 | Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication. |
| CVE-2022-30740 | Media (4.3) | 0.21% | — | 7 jun 2022 | Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers. |
| CVE-2022-30738 | Media (4.3) | 0.54% | — | 7 jun 2022 | Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script. |
| CVE-2022-27839 | Media (4) | 0.57% | — | 11 abr 2022 | Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials. |
| CVE-2022-22290 | Media (6.5) | 0.79% | — | 14 ene 2022 | Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page. |
| CVE-2022-22284 | Media (5.5) | 0.22% | — | 10 ene 2022 | Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication |
| CVE-2021-25521 | Baja (3.3) | 0.21% | — | 8 dic 2021 | Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet. |
| CVE-2021-25520 | Media (6.1) | 0.41% | — | 8 dic 2021 | Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet. |
| CVE-2021-25466 | Media (5.9) | 0.77% | — | 9 sept 2021 | Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token. |
| CVE-2021-25445 | Media (5.3) | 0.75% | — | 5 ago 2021 | Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet. |
| CVE-2021-25419 | Media (6.5) | 0.76% | — | 11 jun 2021 | Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link. |
| CVE-2021-25418 | Alta (7.8) | 0.23% | — | 11 jun 2021 | Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition. |
| CVE-2021-25400 | Alta (7.8) | 0.23% | — | 11 jun 2021 | Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action. |
| CVE-2021-25366 | Baja (2.9) | 0.27% | — | 25 mar 2021 | Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication. |
| CVE-2021-25354 | Media (5.3) | 0.46% | — | 25 mar 2021 | Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink. |
| CVE-2021-25348 | Baja (2.4) | 0.27% | — | 4 mar 2021 | Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission. |