CVE detail
CVE-2024-20837 — CVE-2024-20837
Published 2024-03-05 · Modified 2026-06-17 · Vendor samsung · Product internet · Source nvd
MEDIUM
severity
CVSS-derived band
0.0015
EPSS probability
exploitation probability, 30d
4.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References