PT-2021-16710 · Samsung · Samsung Internet
Sayed Abdelhafiz
·
Published
2021-12-08
·
Updated
2021-12-13
·
CVE-2021-25520
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung Internet versions prior to 16.0.2
Description
The issue is related to insecure caller check and input validation vulnerabilities in the SearchKeyword deeplink logic. This allows untrusted applications to execute script codes in Samsung Internet.
Recommendations
For versions prior to 16.0.2, update to version 16.0.2 or later to resolve the issue.
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samsung Internet