PT-2021-16559 · Samsung · Samsung Internet

CVE-2021-25366

·

Published

2021-03-25

·

Updated

2022-09-23

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Samsung Internet versions prior to 13.2.1.70
Description: The issue is related to improper access control, allowing physically proximate attackers to bypass the secret mode's authentication. This could potentially lead to unauthorized access to sensitive information.
Recommendations: For versions prior to 13.2.1.70, update to version 13.2.1.70 or later to resolve the issue. As a temporary workaround, consider disabling the secret mode feature until a patch is available. Restrict physical access to devices using Samsung Internet to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25366

Affected Products

Samsung Internet