CVE-2025-32407
- EPSS 0.01%
- Veröffentlicht 16.05.2025 00:00:00
- Zuletzt bearbeitet 12.06.2025 16:30:02
Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user. This is a critical misconfigura...
CVE-2024-34671
- EPSS 0.03%
- Veröffentlicht 08.10.2024 07:15:05
- Zuletzt bearbeitet 21.11.2024 09:19:10
Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.
CVE-2024-20869
- EPSS 0.02%
- Veröffentlicht 07.05.2024 05:15:51
- Zuletzt bearbeitet 17.07.2025 19:57:55
Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.
CVE-2024-20838
- EPSS 0.02%
- Veröffentlicht 05.03.2024 05:15:11
- Zuletzt bearbeitet 23.12.2024 16:32:27
Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code.
CVE-2024-20837
- EPSS 0.09%
- Veröffentlicht 05.03.2024 05:15:11
- Zuletzt bearbeitet 23.12.2024 16:29:57
Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.
CVE-2024-20829
- EPSS 0.13%
- Veröffentlicht 05.03.2024 05:15:08
- Zuletzt bearbeitet 14.02.2025 17:27:10
Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.
CVE-2024-20828
- EPSS 0.1%
- Veröffentlicht 06.02.2024 03:15:11
- Zuletzt bearbeitet 21.11.2024 08:53:13
Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.
CVE-2023-30704
- EPSS 0.06%
- Veröffentlicht 10.08.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 08:00:43
Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.
CVE-2023-30674
- EPSS 0.1%
- Veröffentlicht 06.07.2023 03:15:12
- Zuletzt bearbeitet 21.11.2024 08:00:39
Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie.
CVE-2022-39873
- EPSS 0.08%
- Veröffentlicht 07.10.2022 15:15:23
- Zuletzt bearbeitet 21.11.2024 07:18:26
Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.