CVE-2025-20994: Samsung Internet
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper handling of insufficient permission in SyncClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to access read and write arbitrary files.
Affected products
- Samsung Internet: before 28.0.0.59 (fixed in 28.0.0.59)
Published 2025-06-04. Last modified 2026-06-17.