Incorrect Default Permissions in Galaxy Watch Gallery by Samsung
CVE-2025-20910
6.2MEDIUM
Summary
The Galaxy Watch Gallery developed by Samsung has been identified with a vulnerability due to incorrect default permissions. This allows local attackers to potentially access sensitive data within the app prior to the SMR Mar-2025 Release 1. Users are advised to ensure that they update their devices to the latest security release to mitigate any risks associated with this vulnerability. Further details can be found on Samsung's security update page.
Affected Version(s)
Samsung Mobile Devices SMR Mar-2025 Release in Android Watch 14
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved