CVE-2024-20837

MEDIUM

Samsung Internet <24.0.0.41 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0009
EPSS Percentile 24.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (1)
samsung/internet < 24.0.0.41
Published Mar 05, 2024
Tracked Since Feb 18, 2026