UXSS in Samsung Internet Browser (CVE-2025-58485 / SVE-2025-1879)
⚔️ Attack Techniques & Methods2026-03-04, 09:11
Voorivex researchers have demonstrated how an intent validation flaw in exported activities leads to Universal Cross-Site Scripting (UXSS). In this attack, an adversary gains access not only to the active session on a vulnerable page but to all open or cached sessions within the browser at the time of exploitation.
The vulnerability required no elevated privileges and was executed entirely within the browser's context. Once successfully exploited, the flaw granted full access to session data.
💬 Discuss
Vulnerabilities
Vendors
Products
Published
2026-03-04, 09:11