CVE-2021-25354: Medium severity samsung internet browser vulnerability
Published Mar 25, 2021
·Updated
Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.
Affected Software
1 affected component
Samsung Internet<13.2.1.46
Event History
Mar 25, 2021
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-25354?
CVE-2021-25354 is a vulnerability in Samsung Internet prior to version 13.2.1.46 that allows attackers to launch a non-exported activity in Samsung Browser via a malicious deeplink.
2
What is the severity of CVE-2021-25354?
The severity of CVE-2021-25354 is medium with a CVSS score of 5.3.
3
How can attackers exploit CVE-2021-25354?
Attackers can exploit CVE-2021-25354 by using a malicious deeplink to launch a non-exported activity in Samsung Browser.
4
Which versions of Samsung Internet are affected by CVE-2021-25354?
Samsung Internet versions prior to 13.2.1.46 are affected by CVE-2021-25354.
5
Is there a fix for CVE-2021-25354?
Yes, upgrading to Samsung Internet version 13.2.1.46 or later will fix CVE-2021-25354.