CVE-2026-21019
- EPSS 0.03%
- Veröffentlicht 13.05.2026 04:56:22
- Zuletzt bearbeitet 13.05.2026 15:33:53
Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code with system privilege.
CVE-2025-21045
- EPSS 0.02%
- Veröffentlicht 10.10.2025 06:33:03
- Zuletzt bearbeitet 09.01.2026 18:11:58
Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.
CVE-2025-21013
- EPSS 0.03%
- Veröffentlicht 06.08.2025 04:23:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time.
CVE-2025-21012
- EPSS 0.02%
- Veröffentlicht 06.08.2025 04:23:25
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.
CVE-2025-21011
- EPSS 0.02%
- Veröffentlicht 06.08.2025 04:23:24
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and body sensors.
CVE-2025-20997
- EPSS 0.07%
- Veröffentlicht 08.07.2025 10:34:26
- Zuletzt bearbeitet 20.01.2026 15:09:19
Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.
CVE-2025-32407
- EPSS 0.04%
- Veröffentlicht 16.05.2025 00:00:00
- Zuletzt bearbeitet 12.06.2025 16:30:02
Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user. This is a critical misconfigura...
CVE-2025-20939
- EPSS 0.06%
- Veröffentlicht 08.04.2025 04:49:41
- Zuletzt bearbeitet 27.01.2026 17:54:54
Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices.
CVE-2025-20945
- EPSS 0.09%
- Veröffentlicht 08.04.2025 04:40:00
- Zuletzt bearbeitet 27.01.2026 17:55:02
Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.
CVE-2025-20910
- EPSS 0.11%
- Veröffentlicht 06.03.2025 05:15:17
- Zuletzt bearbeitet 02.02.2026 18:14:07
Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.