CVE-2025-58485Disclosure(samsung / internet)

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch samsung internet systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script.

2.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • internet

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-02-20); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
internet

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-20: 1Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-03-04: 1Mentions · 2026-03-21: 1PoC Mentioned / Linked · 2026-02-20: 1PoC Mentioned / Linked · 2026-02-23: 1PoC Mentioned / Linked · 2026-03-04: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-20: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-21: 102-2002-2302-2403-0403-21
Signal classification3 categories
Disclosure
240.0%
General
240.0%
PoC
120.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-201
Disclosure1
2026-02-231
General1
2026-02-241
General1
2026-03-041
PoC1
2026-03-211
Disclosure1
Full discourse5 posts
  • YS@YShahinzadeh
    General

    It's time for sharing, this is not a simple write-up, we are sharing our methodology and reasoning, detailing how we approached and hunted the flaw, I hope you like it :] https://blog.voorivex.team/uxss-on-samsung-browser-cve-2025-58485-sve-2025-1879 https://t.co/Ic6RbsQutn

    Post summary

    The tweet announces a forthcoming blog post that explains how the authors discovered and analyzed the Samsung browser flaw (CVE-2025-58485/CVE-2025-1879), but it provides no concrete exploit code, patch, or confirmation of active exploitation.

    1248128119916.3K
    17.4K followersView on X
  • Omid Rezaei@omidxrz
    Disclosure

    We got permission from the Samsung Security team to disclose this uXSS that we found in Samsung Browser, it was assigned a CVE (CVE-2025-58485) and patched. Here is the PoC, expect the write-up in the next upcoming days. https://t.co/KuyjCdLYbm

    Post summary

    Samsung’s security team disclosed a user-based XSS vulnerability (CVE-2025-58485) in its browser, shared a PoC link, and noted that the issue has already been patched.

    9110183358.2K
    6.5K followersView on X
  • Muqsit 𝕏@mqst_
    Disclosure

    ☂️ Universal Cross-Site Scripting (UXSS) Vulnerability in the Samsung Internet Browser. Blog: https://blog.voorivex.team/uxss-on-samsung-browser-cve-2025-58485-sve-2025-1879 Authors: @YShahinzadeh & @omidxrz https://t.co/xfM353bcwx

    Post summary

    A new Universal Cross‑Site Scripting vulnerability in the Samsung Internet Browser has been disclosed, with details available in an external blog post.

    018183554.0K
    11.9K followersView on X
  • Dinesh Shetty@Din3zh
    General

    uXSS on Samsung Browser [CVE-2025-58485 SVE-2025-1879] - https://blog.voorivex.team/uxss-on-samsung-browser-cve-2025-58485-sve-2025-1879 #MobileSecurity #AndroidSecurity #samsung

    Post summary

    The post references a uXSS vulnerability in Samsung Browser (CVE-2025-58485) and provides a link to a blog, but no further details are given in the text.

    020122528
    2.6K followersView on X
  • dbugs@ptdbugs
    PoC

    UXSS in Samsung Internet Browser (CVE-2025-58485 / SVE-2025-1879) Voorivex researchers have demonstrated how an intent validation flaw in exported activities leads to Universal Cross-Site Scripting (UXSS). In this attack, an adversary gains access not only to the active session on a vulnerable page but to all open or cached sessions within the browser at the time of exploitation. The vulnerability required no elevated privileges and was executed entirely within the browser's context. Once successfully exploited, the flaw granted full access to session data. 🔗 Article: https://blog.voorivex.team/uxss-on-samsung-browser-cve-2025-58485-sve-2025-1879 #dbugs_attacks

    Post summary

    Voorivex researchers demonstrated a UXSS vulnerability (CVE‑2025‑58485) in Samsung Internet Browser, giving attackers full session access without elevated privileges; no active exploitation or patches are mentioned.

    00010201
    551 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsamsunginternet---

Explore more