PT-2021-16559 · Samsung · Samsung Internet
Published
2021-03-25
·
Updated
2022-09-23
·
CVE-2021-25366
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Samsung Internet versions prior to 13.2.1.70
Description:
The issue is related to improper access control, allowing physically proximate attackers to bypass the secret mode's authentication. This could potentially lead to unauthorized access to sensitive information.
Recommendations:
For versions prior to 13.2.1.70, update to version 13.2.1.70 or later to resolve the issue. As a temporary workaround, consider disabling the secret mode feature until a patch is available. Restrict physical access to devices using Samsung Internet to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Internet