Samsung Internet: Your monthly security patch never reaches it

Once a month, the same notification. Software update available, a few hundred megabytes, restart. Afterwards the menu shows a fresh date next to the security patch, and the matter feels settled.
For most of the system that is true. In July, Samsung's update went to the newest models first.
One of the most important components on the device never sees that patch. The preinstalled browser gets its updates from somewhere else, through the Play Store and the Galaxy Store. Two separate routes, and only one of them is announced to you.
How old the core of that browser currently is cannot be established from the outside. Not because nobody cares, but because Samsung has not published it for Android in more than two years.

Why that number matters at all becomes clear once you look at what sits inside such a browser.
Samsung's browser is not built from the ground up. It rests on Chromium, the open-source foundation that Google Chrome, Edge and Opera are built from as well. One part of it is called V8, and it executes JavaScript, the program code that almost every website brings along. Flaws in V8 are therefore particularly awkward, opening a prepared page is enough.
Such flaws get found and fixed, and once fixed they are documented publicly, description included. Anyone who wants to attack a device that is missing the correction does not have to discover anything new. He reads up. The industry calls that an N-day, as opposed to a zero-day that nobody knows about yet.
What that looks like in practice was shown by the security firm OtterSec on 1 April 2026, together with the group Crusaders of Rust. To get there, the researchers had to do exactly what an ordinary user cannot. They pulled the browser app off a Galaxy S25 and searched the program files for the version number. What they found was V8 13.6, half a year old at that point.
They then built an attack out of a hole that Google had long since closed in Chrome. In the end they were able to run their own machine code inside the browser and execute foreign code in the name of arbitrary websites. A prepared page could have reached the contents of other open pages that way, a mailbox for instance, or an account at an online shop.
That last step only worked because Android walls the browser off more weakly than a computer does. On a PC practically every website gets its own process. On Android only pages with a login and a few specially marked ones do. The rest share one.
Security research has its own name for this distance. Patch gap, the stretch between the moment a flaw is fixed upstream in the Chromium project and the moment the correction arrives downstream with the user. For as long as that stretch lasts, a set of instructions lies out in the open while the device is still vulnerable. With Chrome itself the window shrinks to days, because Google builds and ships the same code. With a browser that a different vendor maintains and distributes through a different channel, it comes down to how quickly that vendor follows.
This particular hole has since been closed. What is open is everything that came after it.
For this article we tried to answer the question ourselves. Which Chromium base does Samsung ship to a Galaxy today?
There is no clear answer. Publicly collected browser identifiers, the strings devices use to announce themselves online, contradict one another for one and the same app version. Some name a base from December 2025, others a much newer one. Collections like these also hold faked and automatically generated entries, so they are no proof.
That leaves the vendor, and for Android the vendor says nothing. The change notes suggest that Samsung does pull corrections into its own build, there is regularly a line about closed security holes. Which ones, it does not say.
That is not a minor point. On 8 June 2026 Google fixed a flaw in V8, rated high severity, and noted that an exploit for it was already in circulation. Whether and when that correction landed in Samsung's browser is not documented publicly.
For the Windows build of the same browser the question would take two minutes. Samsung puts it on its own page.
In everyday terms this does not mean every Galaxy is exposed. It means nobody outside Samsung can check whether it is. For a program that opens foreign content from the internet every day and comes preinstalled on several hundred million devices, that difference is larger than it sounds.

Checking which build runs on your own device takes half a minute. On the home screen or in the app drawer, press and hold the browser icon, then usually tap a small "i". The app info shows the version number. The Play Store entry shows the same value.
Whether an update is waiting shows up in the Play Store or the Galaxy Store as well. If there is a button to update, something has moved.
What that number says about the Chromium base underneath stays open. That is exactly the point.
Anyone who finds that too vague installs a second browser. Chrome and Firefox come straight from their makers, name their version number in the menu and renew their underpinnings independently of Samsung's schedule. They can be set as the default in Android's settings under default apps.
Anyone who wants to stay with Samsung's browser, and there are good reasons to, among them the built-in ad blocker and the tie-in with Samsung Pass, should at least leave automatic updates switched on in the store. Then every build Samsung releases arrives without any action. There is no more control to be had at this point.
The monthly patch still matters. It closes holes in the system that no browser update can reach. It just is not responsible for everything on the device that goes online.
Source(s)
OtterSec, Patch gap to mobile renderer RCE, 1 April 2026
Samsung Developer, Release note Samsung Internet for Android
Samsung Developer, Release note Samsung Internet for Windows
Chrome Releases, Stable Channel Update for Desktop, 8 June 2026
Samsung, Use the Samsung Browser app on a Galaxy phone or tablet





