Vulnerability Details CVE-2024-20837
Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.7%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2024-20837
-
cpe:2.3:a:samsung:internet:-
-
cpe:2.3:a:samsung:internet:13.2.1.46
-
cpe:2.3:a:samsung:internet:13.2.1.70
-
cpe:2.3:a:samsung:internet:14.0.1.20
-
cpe:2.3:a:samsung:internet:14.0.1.62
-
cpe:2.3:a:samsung:internet:16.0.6.23
-
cpe:2.3:a:samsung:internet:24.0