The Samsung Internet Browser pre-installed on Android devices is affected by a critical SOP bypass issue, tracked as CVE-2017-17692. The vulnerability is a Same Origin Policy (SOP) bypass issue that affects the Samsung Internet browser version 5.4.02.3 and earlier. An attacker can copy victims session cookie or hijack his session and read and write webmail on behalf of the attacker. Samsung confirmed that the patch is already preloaded in our upcoming model Galaxy Note 8, and the application will be updated in October.”]
Source: http://securityaffairs.co/wordpress/67235/hacking/samsung-sop-bypass-issue.html

