CVE-2022-22290: Medium severity samsung internet browser vulnerability
Published Jan 14, 2022
·Updated
Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.
Affected Software
1 affected component
Samsung Internet<16.0.6.23
Event History
Jan 14, 2022
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22290.
2
What is the affected software?
The affected software is Samsung Internet prior to version 16.0.6.23.
3
What is the severity of CVE-2022-22290?
The severity of CVE-2022-22290 is medium with a severity value of 6.5.
4
How can attackers exploit CVE-2022-22290?
Attackers can exploit CVE-2022-22290 by performing domain spoofing via a crafted HTML page in the Downloads section of Samsung Internet.
5
How can I fix this vulnerability?
To fix this vulnerability, users should update Samsung Internet to version 16.0.6.23 or later.