Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 | Vendor Advisory |
https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 | Vendor Advisory |
Configurations
History
23 Dec 2024, 16:29
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:samsung:internet:*:*:*:*:*:*:*:* | |
First Time |
Samsung internet
Samsung |
|
References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 - Vendor Advisory |
21 Nov 2024, 08:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 - |
05 Mar 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-05 05:15
Updated : 2024-12-23 16:29
NVD link : CVE-2024-20837
Mitre link : CVE-2024-20837
CVE.ORG link : CVE-2024-20837
JSON object : View
Products Affected
samsung
- internet
CWE