PT-2021-16559 · Samsung · Samsung Internet

Published

2021-03-25

·

Updated

2022-09-23

·

CVE-2021-25366

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Samsung Internet versions prior to 13.2.1.70
Description: The issue is related to improper access control, allowing physically proximate attackers to bypass the secret mode's authentication. This could potentially lead to unauthorized access to sensitive information.
Recommendations: For versions prior to 13.2.1.70, update to version 13.2.1.70 or later to resolve the issue. As a temporary workaround, consider disabling the secret mode feature until a patch is available. Restrict physical access to devices using Samsung Internet to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2021-25366

Affected Products

Samsung Internet