Notebookcheck Logo

Samsung Internet: Your monthly security patch never reaches it

A Samsung Galaxy S25 Ultra standing upright on a table, an open website visible on the display
ⓘ Notebookcheck
Samsung’s own browser comes preinstalled on Galaxy devices. Which Chromium base sits inside it is something Samsung does not publish for Android.
Samsung ships a security patch every month. It does not renew the preinstalled browser, which gets its updates through the Play Store and the Galaxy Store instead. And which Chromium base it builds on there is something Samsung has not published for Android in more than two years. What researchers found on a Galaxy S25, and how to check which build is running on your phone.

Once a month, the same notification. Software update available, a few hundred megabytes, restart. Afterwards the menu shows a fresh date next to the security patch, and the matter feels settled.

For most of the system that is true. In July, Samsung's update went to the newest models first.

One of the most important components on the device never sees that patch. The preinstalled browser gets its updates from somewhere else, through the Play Store and the Galaxy Store. Two separate routes, and only one of them is announced to you.

How old the core of that browser currently is cannot be established from the outside. Not because nobody cares, but because Samsung has not published it for Android in more than two years.

Comparison of Samsung release notes, on the left Android with a last entry from 2024, on the right Windows with an entry from August 2026.
ⓘ Notebookcheck
Samsung keeps the change list for the Windows build current. For Android it ends in May 2024.

Why that number matters at all becomes clear once you look at what sits inside such a browser.

Samsung's browser is not built from the ground up. It rests on Chromium, the open-source foundation that Google Chrome, Edge and Opera are built from as well. One part of it is called V8, and it executes JavaScript, the program code that almost every website brings along. Flaws in V8 are therefore particularly awkward, opening a prepared page is enough.

Such flaws get found and fixed, and once fixed they are documented publicly, description included. Anyone who wants to attack a device that is missing the correction does not have to discover anything new. He reads up. The industry calls that an N-day, as opposed to a zero-day that nobody knows about yet.

What that looks like in practice was shown by the security firm OtterSec on 1 April 2026, together with the group Crusaders of Rust. To get there, the researchers had to do exactly what an ordinary user cannot. They pulled the browser app off a Galaxy S25 and searched the program files for the version number. What they found was V8 13.6, half a year old at that point.

They then built an attack out of a hole that Google had long since closed in Chrome. In the end they were able to run their own machine code inside the browser and execute foreign code in the name of arbitrary websites. A prepared page could have reached the contents of other open pages that way, a mailbox for instance, or an account at an online shop.

That last step only worked because Android walls the browser off more weakly than a computer does. On a PC practically every website gets its own process. On Android only pages with a login and a few specially marked ones do. The rest share one.

Security research has its own name for this distance. Patch gap, the stretch between the moment a flaw is fixed upstream in the Chromium project and the moment the correction arrives downstream with the user. For as long as that stretch lasts, a set of instructions lies out in the open while the device is still vulnerable. With Chrome itself the window shrinks to days, because Google builds and ships the same code. With a browser that a different vendor maintains and distributes through a different channel, it comes down to how quickly that vendor follows.

This particular hole has since been closed. What is open is everything that came after it.

For this article we tried to answer the question ourselves. Which Chromium base does Samsung ship to a Galaxy today?

There is no clear answer. Publicly collected browser identifiers, the strings devices use to announce themselves online, contradict one another for one and the same app version. Some name a base from December 2025, others a much newer one. Collections like these also hold faked and automatically generated entries, so they are no proof.

That leaves the vendor, and for Android the vendor says nothing. The change notes suggest that Samsung does pull corrections into its own build, there is regularly a line about closed security holes. Which ones, it does not say.

That is not a minor point. On 8 June 2026 Google fixed a flaw in V8, rated high severity, and noted that an exploit for it was already in circulation. Whether and when that correction landed in Samsung's browser is not documented publicly.

For the Windows build of the same browser the question would take two minutes. Samsung puts it on its own page.

In everyday terms this does not mean every Galaxy is exposed. It means nobody outside Samsung can check whether it is. For a program that opens foreign content from the internet every day and comes preinstalled on several hundred million devices, that difference is larger than it sounds.

Comparison of the two update routes on a Galaxy, on the left the monthly security patch, on the right the browser update through the store.
ⓘ Notebookcheck
The monthly patch and the browser update arrive through different channels. Only one of them is announced.

Checking which build runs on your own device takes half a minute. On the home screen or in the app drawer, press and hold the browser icon, then usually tap a small "i". The app info shows the version number. The Play Store entry shows the same value.

Whether an update is waiting shows up in the Play Store or the Galaxy Store as well. If there is a button to update, something has moved.

What that number says about the Chromium base underneath stays open. That is exactly the point.

Anyone who finds that too vague installs a second browser. Chrome and Firefox come straight from their makers, name their version number in the menu and renew their underpinnings independently of Samsung's schedule. They can be set as the default in Android's settings under default apps.

Anyone who wants to stay with Samsung's browser, and there are good reasons to, among them the built-in ad blocker and the tie-in with Samsung Pass, should at least leave automatic updates switched on in the store. Then every build Samsung releases arrives without any action. There is no more control to be had at this point.

The monthly patch still matters. It closes holes in the system that no browser update can reach. It just is not responsible for everything on the device that goes online.

Google LogoAdd as a preferred source on Google
Mail Logo
> Expert Reviews and News on Laptops, Smartphones and Tech Innovations > Reviews > Samsung Internet: Your monthly security patch never reaches it
Steffen Zahn, 2026-08-21 (Update: 2026-08-21)