CVE-2025-20994: High severity samsung internet browser vulnerability
Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to access read and write arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20994?
CVE-2025-20994 has a moderate severity level due to insufficient permission handling that could allow local attackers to access sensitive files.
How do I fix CVE-2025-20994?
To fix CVE-2025-20994, update Samsung Internet to version 28.0.0.59 or later on non-Samsung devices.
Who is affected by CVE-2025-20994?
CVE-2025-20994 affects users of Samsung Internet on non-Samsung devices prior to version 28.0.0.59.
What kind of attack is enabled by CVE-2025-20994?
CVE-2025-20994 allows local attackers to read and write arbitrary files, potentially compromising user data.
Is CVE-2025-20994 specific to Samsung devices?
No, CVE-2025-20994 specifically affects Samsung Internet installed on non-Samsung devices prior to version 28.0.0.59.