PT-2021-16711 · Samsung · Samsung Internet
Published
2021-12-08
·
Updated
2021-12-13
·
CVE-2021-25521
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung Internet versions prior to 16.0.2
Description
The issue is related to an insecure caller check in the sharevia deeplink logic, allowing untrusted applications to obtain the current tab URL in Samsung Internet.
Recommendations
For versions prior to 16.0.2, update to version 16.0.2 or later to resolve the issue.
Fix
Improper Authorization
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samsung Internet