Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.
References
Link | Resource |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 | Vendor Advisory |
https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 | Vendor Advisory |
Configurations
History
23 Dec 2024, 16:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.samsungmobile.com/serviceWeb.smsb?year=2024&month=03 - Vendor Advisory | |
CPE | cpe:2.3:a:samsung:internet:*:*:*:*:*:*:*:* | |
First Time |
Samsung
Samsung internet |
|
CWE | NVD-CWE-noinfo |
Information
Published : 2024-03-05 05:15
Updated : 2024-12-23 16:29
NVD link : CVE-2024-20837
Mitre link : CVE-2024-20837
CVE.ORG link : CVE-2024-20837
JSON object : View
Products Affected
samsung
- internet
CWE