CVE-2024-20837: Samsung Internet

Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.

Affected products

  • Samsung Internet: before 24.0.0.41 (fixed in 24.0.0.41)

Published 2024-03-05. Last modified 2026-06-17.