CVE-2024-20837: Medium severity samsung internet browser vulnerability
Published Mar 5, 2024
·Updated
Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.
Affected Software
1 affected component
Samsung Internet<24.0.0.41
Event History
Mar 5, 2024
CVE Published
via MITRE·04:44 AM
Data Sourced
via MITRE·04:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-20837?
CVE-2024-20837 has been rated as a moderate severity vulnerability due to the potential for unauthorized permission granting.
2
How do I fix CVE-2024-20837?
To mitigate CVE-2024-20837, update Samsung Internet to version 24.0.0.41 or later.
3
What type of attack does CVE-2024-20837 facilitate?
CVE-2024-20837 allows local attackers to grant permission for their own Trusted Web Activities without user interaction.
4
Which versions of Samsung Internet are affected by CVE-2024-20837?
CVE-2024-20837 affects all versions of Samsung Internet prior to 24.0.0.41.
5
Who is impacted by CVE-2024-20837?
Users of Samsung Internet prior to version 24.0.0.41 are at risk of exploitation from local attackers.