PT-2024-18779 · Samsung · Samsung Internet
Narendra Bhati
·
Published
2024-05-07
·
Updated
2025-07-17
·
CVE-2024-20869
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung Internet versions prior to 25.0.0.41
Description
The issue is related to improper privilege management, allowing local attackers to bypass protection for cookies. This enables them to access sensitive information without proper authorization.
Recommendations
For versions prior to 25.0.0.41, update to version 25.0.0.41 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive cookies until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samsung Internet