Samsung Internet Improper Permission Handling Vulnerability in SyncClientProvider on Non-Samsung Devices

Vulnerability

A vulnerability exists in Samsung Internet, specifically in the SyncClientProvider component, on non-Samsung devices running versions prior to 28.0.0.59. This vulnerability allows local attackers to read and write arbitrary files due to improper handling of permissions. The issue has been addressed in version 28.0.0.59.

Impact

Exploitation of this vulnerability could lead to unauthorized access to read and write files on the affected device.

Remediation

Users can update to Samsung Internet version 28.0.0.59 or later to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.0
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.