CVE-2025-20995: Samsung Internet

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and write arbitrary files.

Affected products

  • Samsung Internet: before 28.0.0.59 (fixed in 28.0.0.59)

Published 2025-06-04. Last modified 2026-06-17.