CVE-2024-20837

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 5, 2024
Updated: Dec 23, 2024

Summary

CVE-2024-20837 is a vulnerability affecting Samsung Internet browsers prior to version 24.0.0.41. This issue involves a flaw in the handling of Trusted Web Activities (TWAs), allowing local attackers to grant permissions to their own TWA WebApps without user interaction. This vulnerability could potentially lead to unauthorized access or data theft, making it a significant security concern for Samsung Internet users. Attackers can exploit this issue by manipulating the TWA permissions process, enabling them to bypass user consent and gain unauthorized access to sensitive information. Users are advised to update their Samsung Internet browsers to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Samsung Internet Browser

Affected Vendors

  • Samsung