Vulnerability Description
Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Internet | < 16.0.6.23 |
Related Weaknesses (CWE)
References
- https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=1Vendor Advisory
- https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=1Vendor Advisory
FAQ
What is CVE-2022-22290?
CVE-2022-22290 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.
How severe is CVE-2022-22290?
CVE-2022-22290 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22290?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung Internet.