PT-2021-16711 · Samsung · Samsung Internet

Published

2021-12-08

·

Updated

2021-12-13

·

CVE-2021-25521

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Internet versions prior to 16.0.2
Description The issue is related to an insecure caller check in the sharevia deeplink logic, allowing untrusted applications to obtain the current tab URL in Samsung Internet.
Recommendations For versions prior to 16.0.2, update to version 16.0.2 or later to resolve the issue.

Fix

Improper Authorization

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25521

Affected Products

Samsung Internet