PT-2024-18779 · Samsung · Samsung Internet

Narendra Bhati

·

Published

2024-05-07

·

Updated

2025-07-17

·

CVE-2024-20869

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samsung Internet versions prior to 25.0.0.41
Description The issue is related to improper privilege management, allowing local attackers to bypass protection for cookies. This enables them to access sensitive information without proper authorization.
Recommendations For versions prior to 25.0.0.41, update to version 25.0.0.41 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive cookies until the update is applied.

Fix

Related Identifiers

CVE-2024-20869

Affected Products

Samsung Internet