Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2025-10891] Patch gap to mobile renderer RCE: pwning Samsung Internet’s V8 on the Galaxy S25

osec.io | research | CVE-2025-10891 | #rce | #xss | #mobile-security | #v8 | #n-day | #samsung-internet

Summary

OtterSec exploits a six-month-old V8 (CVE-2025-10891) in Samsung Internet on the Galaxy S25, achieving renderer RCE and universal XSS via the n-day patch gap.
Published
Collected

original ↗

Related coverage

back