PT-2025-15340 · Samsung · Galaxy Watch
Published
2025-04-08
·
Updated
2026-01-27
·
CVE-2025-20939
CVSS v3.1
5.4
Medium
| Vector | AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions:
Galaxy Watch versions prior to SMR Apr-2025 Release 1
Description:
The issue is related to improper authorization in the wireless download protocol, allowing physical attackers to update the device unique identifier of Watch devices. This could potentially lead to unauthorized access or changes to device settings.
Recommendations:
For Galaxy Watch versions prior to SMR Apr-2025 Release 1, update to the SMR Apr-2025 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting physical access to the device to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Galaxy Watch