First published: Wed Dec 08 2021(Updated: )
Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Internet | <16.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-25520.
The title of this vulnerability is 'Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to ...'.
The description of this vulnerability is 'Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.'
The Samsung Internet version prior to 16.0.2 is affected by this vulnerability.
The severity of CVE-2021-25520 is medium with a CVSS score of 6.1.
To fix this vulnerability, update to a version of Samsung Internet that is equal to or greater than 16.0.2.