CVE-2021-25520

MEDIUM

Samsung Internet < 16.0.2 - Unauthenticated Script Execution via SearchKeyword Deeplink

Title source: llm
STIX 2.1

Description

Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0027
EPSS Percentile 50.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-20 CWE-79
Status published
Products (1)
samsung/internet < 16.0.2
Published Dec 08, 2021
Tracked Since Feb 18, 2026