PT-2023-22871 · Samsung · Samsung Internet

Mohit Raj

+1

·

Published

2023-07-06

·

Updated

2023-07-12

·

CVE-2023-30674

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Internet versions prior to 21.0.0.41
Description The issue is related to an improper configuration that allows an attacker to bypass SameSite Cookie restrictions. This could potentially lead to security breaches, although specific details about the estimated number of affected devices or real-world incidents are not provided.
Recommendations For versions prior to 21.0.0.41, update to version 21.0.0.41 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive cookies to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2023-30674

Affected Products

Samsung Internet