PT-2021-16547 · Samsung · Samsung Internet

Published

2021-03-25

·

Updated

2023-06-30

·

CVE-2021-25354

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Samsung Internet versions prior to 13.2.1.46
Description: The issue is related to an improper input check in Samsung Internet, which allows attackers to launch non-exported activity in Samsung Browser via a malicious deeplink.
Recommendations: For versions prior to 13.2.1.46, update to version 13.2.1.46 or later to resolve the issue. As a temporary workaround, consider restricting the use of deeplinks in Samsung Browser until the update is applied.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-25354

Affected Products

Samsung Internet