UXSS in Samsung Internet Browser (CVE-2025-58485 / SVE-2025-1879)

Voorivex researchers have demonstrated how an intent validation flaw in exported activities leads to Universal Cross-Site Scripting (UXSS). In this attack, an adversary gains access not only to the active session on a vulnerable page but to all open or cached sessions within the browser at the time of exploitation.
The vulnerability required no elevated privileges and was executed entirely within the browser's context. Once successfully exploited, the flaw granted full access to session data.
💬 Discuss
Vulnerabilities
5.5
CVE-2025-58485
Vendors
Samsung
Products
Samsung Internet Browser
Published
2026-03-04, 09:11