CVE-2021-25348: Low severity samsung internet browser vulnerability
Published Mar 4, 2021
·Updated
Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.
Affected Software
1 affected component
Samsung Internet<13.0.1.60
Event History
Mar 4, 2021
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-25348.
2
What is the severity of CVE-2021-25348?
The severity of CVE-2021-25348 is low (CVSS score: 2.4).
3
Which software versions are affected by CVE-2021-25348?
Samsung Internet versions prior to 13.0.1.60 are affected by CVE-2021-25348.
4
What is the impact of CVE-2021-25348?
CVE-2021-25348 allows unauthorized access to files in internal storage without the required STORAGE permission.
5
How can I fix CVE-2021-25348?
To fix CVE-2021-25348, update Samsung Internet to version 13.0.1.60 or later.