First published: Thu Mar 04 2021(Updated: )
Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Internet | <13.0.1.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-25348.
The severity of CVE-2021-25348 is low (CVSS score: 2.4).
Samsung Internet versions prior to 13.0.1.60 are affected by CVE-2021-25348.
CVE-2021-25348 allows unauthorized access to files in internal storage without the required STORAGE permission.
To fix CVE-2021-25348, update Samsung Internet to version 13.0.1.60 or later.