ANDROID Compaq QTab Ultra 12.6 Android tablet launches in Mexico for $502 ANDROID Google Pixel 11 Pro Fold Fails Bend Test Despite 3x Durability Claim ANDROID Honor Pad X10 Pro Max: 13-inch tablet with 10,100mAh battery ships Aug 28 PHONES REDMI K100 Pro Max Sales Hit 135% of Predecessor in First Week PC HARDWARE HP OmniBook 3 brings Snapdragon X1 laptop for around $500 PC HARDWARE AOC Q27G4ZRAD/01 Monitor Launches at $312 With 260 Hz Refresh Rate LINUX Bazzite Deck 44 Brings SteamOS-Aligned Stack to Linux Handhelds PROTON Valve Steam Frame Compatibility Hits 89 Games With Portal 2 Added GAMES Microsoft Xbox Layoffs: Bethesda Workers Protest Yearly Cuts NINTENDO SWITCH Neverway delayed to 2027 as Coldblood Inc. refines horror RPG GAMES Vampire Survivors DLC Legacy of the Bloodmoon Launches August 28 PLAYSTATION 5 The Blood of Dawnwalker Console Footage Reveals 4K Performance Modes STEAM Tails of Iron II Whiskers of Winter Free Expansion Blood and Brine Now Live GAMES Xbox CTO Backs Rockstar in Fight Against GTA 6 Leaks

Samsung Internet Lags Android Security Patches, Leaving Galaxy Users Exposed

Simon Ellis 0 comments 2 min read

Samsung Internet for Android misses monthly OS security patches, leaving Galaxy users exposed to known V8 engine flaws and cross- tab data risks.

Samsung Internet Lags Android Security Patches, Leaving Galaxy Users Exposed
ANDROID

Samsung Internet for Android leaves Galaxy users exposed to known browser vulnerabilities because its update cycle does not align with the monthly Android security patches that protect the rest of the operating system. This gap matters because attackers can exploit unpatched engine flaws to gain access to sensitive data stored across different browser tabs. Users relying on the preinstalled browser for daily tasks face a higher risk of cross-tab data leakage compared to those on platforms with tighter process isolation.

Separate update cycle leaves browser engine vulnerable to known exploits

The browser runs on the V8 JavaScript engine, which powers Chrome and many other web applications. Researchers from OtterSec and Crusaders of Rust demonstrated a remote code execution exploit in April 2026 by targeting V8 version 13.6. This specific version of the engine was already half a year old at the time of the demonstration, highlighting a significant lag in security updates.

Android's security model for browsers relies on process isolation to prevent compromised applications from accessing data in other tabs. However, this isolation is weaker on mobile operating systems than on personal computers, making successful exploits more dangerous. If the browser is compromised, an attacker can potentially read data from other open tabs, including banking sessions or private browsing windows.

Google addressed a high-severity flaw in the V8 engine on June 8, 2026, but it remains unconfirmed whether Samsung Internet received this specific patch. Samsung has not published Android release notes since May 2024, so there is no public record of which security holes were closed in recent updates. The exact Chromium base version running on current Samsung Internet builds is also unknown, as public browser identifiers contradict each other and Samsung does not document its Android release details.

Samsung Internet updates are distributed through the Play Store and Galaxy Store, operating independently from the monthly OS security patch cycle. This separate update mechanism means that critical security fixes for the browser engine may not reach users until Samsung decides to push a standalone browser update. The Windows build of Samsung Internet is kept current, but the Android version lacks this same level of timely maintenance transparency.

Source: Samsung Internet, NotebookCheck

Discussion

0 comments

Leave a comment