CVE-2022-25824

MEDIUM

BixbyTouch < 2.2.00.6 - Unauthenticated Arbitrary URL and Local File Load in WebView

Title source: llm
STIX 2.1

Description

Improper access control vulnerability in BixbyTouch prior to version 2.2.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

References (1)

Core 1
Core References

Scores

CVSS v3 4.0
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-284
Status published
Products (1)
samsung/bixby_touch < 2.2.00.6
Published Mar 10, 2022
Tracked Since Feb 18, 2026