ANDROID Samsung One UI 9 requires manual activation for key theft protection features PHONES FCC Approves SpaceX Starlink Mobile to Launch 15,000 Satellites for 150Mbps Direct-to-Device Service ANDROID Supermassive Games makes The Conjuring a Netflix-exclusive mobile horror game GAMES Battlefield 6 fans call anniversary event a slap in the face as community compares rewards to free-to-play titles GAMES Star Wars: Galactic Racer launches with pod racing in the Outer Rim STEAM 25 Steam Deck Games Hit 90% Discount in Valve’s Autumn Sale GAMES League of Legends Patch 26.20 Set as Official Balance for Worlds 2026 GAMES Gears of War 3 Unofficial PC Port Fixes Campaign-Breaking Soft-Locks, Enables Full Completion STEAM Bloodborne PC Port Fails to Beat Emulation on Steam Deck, Reviewer Advises Against It CONSOLES Apex Legends forces cross-play on consoles in US-West to cut queue times GAMES FBI arrests Fortnite player for threats after Epic Games hands over voice chat recordings GAMES Marvel Rivals launches ‘Path to Doomsday: Infinity War’ event with new narrative objectives CONSOLES PS6 Handheld Rumors Point to SD Card Slot for Expandable Storage CONSOLES Sony certifies PlayStation Portal successor models CFI-Y2000 and CFI-Y2105

Samsung Internet Lags Android Security Patches, Leaving Galaxy Users Exposed

Simon Ellis 2 min read

Samsung Internet for Android misses monthly OS security patches, leaving Galaxy users exposed to known V8 engine flaws and cross- tab data risks.

Samsung Internet Lags Android Security Patches, Leaving Galaxy Users Exposed
ANDROID

Samsung Internet for Android leaves Galaxy users exposed to known browser vulnerabilities because its update cycle does not align with the monthly Android security patches that protect the rest of the operating system. This gap matters because attackers can exploit unpatched engine flaws to gain access to sensitive data stored across different browser tabs. Users relying on the preinstalled browser for daily tasks face a higher risk of cross-tab data leakage compared to those on platforms with tighter process isolation.

Separate update cycle leaves browser engine vulnerable to known exploits

The browser runs on the V8 JavaScript engine, which powers Chrome and many other web applications. Researchers from OtterSec and Crusaders of Rust demonstrated a remote code execution exploit in April 2026 by targeting V8 version 13.6. This specific version of the engine was already half a year old at the time of the demonstration, highlighting a significant lag in security updates.

Android's security model for browsers relies on process isolation to prevent compromised applications from accessing data in other tabs. However, this isolation is weaker on mobile operating systems than on personal computers, making successful exploits more dangerous. If the browser is compromised, an attacker can potentially read data from other open tabs, including banking sessions or private browsing windows.

Google addressed a high-severity flaw in the V8 engine on June 8, 2026, but it remains unconfirmed whether Samsung Internet received this specific patch. Samsung has not published Android release notes since May 2024, so there is no public record of which security holes were closed in recent updates. The exact Chromium base version running on current Samsung Internet builds is also unknown, as public browser identifiers contradict each other and Samsung does not document its Android release details.

Samsung Internet updates are distributed through the Play Store and Galaxy Store, operating independently from the monthly OS security patch cycle. This separate update mechanism means that critical security fixes for the browser engine may not reach users until Samsung decides to push a standalone browser update. The Windows build of Samsung Internet is kept current, but the Android version lacks this same level of timely maintenance transparency.

Source: Samsung Internet, NotebookCheck