Skip to main content

Vendor/product archive

samsung / internet CVEs

Beta · best-effort

29 CVEs tagged to samsung / internet0 Critical, 2 High, 20 Medium, 7 Low, 0 Unrated.

CVE-2026-21036

Published Jun 5, 2026

Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58485

Published Dec 2, 2025

Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20995

Published Jun 4, 2025

Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and wr…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-20994

Published Jun 4, 2025

Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to access…

CVSS 4.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-32407

Published May 16, 2025

Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate an…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34671

Published Oct 8, 2024

Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interacti…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-20869

Published May 7, 2024

Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20838

Published Mar 5, 2024

Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20837

Published Mar 5, 2024

Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebA…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20829

Published Mar 5, 2024

Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20828

Published Feb 6, 2024

Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authe…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-30704

Published Aug 10, 2023

Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-30674

Published Jul 6, 2023

Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39873

Published Oct 7, 2022

Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30740

Published Jun 7, 2022

Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30738

Published Jun 7, 2022

Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27839

Published Apr 11, 2022

Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-22290

Published Jan 14, 2022

Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22284

Published Jan 10, 2022

Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25521

Published Dec 8, 2021

Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25520

Published Dec 8, 2021

Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25466

Published Sep 9, 2021

Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25445

Published Aug 5, 2021

Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25419

Published Jun 11, 2021

Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25418

Published Jun 11, 2021

Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 29 CVEsPage 1 of 2