First published: Tue Mar 05 2024(Updated: )
Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Internet | <24.0.0.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20837 has been rated as a moderate severity vulnerability due to the potential for unauthorized permission granting.
To mitigate CVE-2024-20837, update Samsung Internet to version 24.0.0.41 or later.
CVE-2024-20837 allows local attackers to grant permission for their own Trusted Web Activities without user interaction.
CVE-2024-20837 affects all versions of Samsung Internet prior to 24.0.0.41.
Users of Samsung Internet prior to version 24.0.0.41 are at risk of exploitation from local attackers.