Improper Access Control in Samsung Galaxy Watch from Samsung Electronics
CVE-2025-20911

4.4MEDIUM

Key Information:

Vendor
Samsung
Vendor
CVE Published:
6 March 2025

Summary

An improper access control vulnerability in the sem_wifi service of Samsung Galaxy Watch devices allows local attackers to gain unauthorized privilege. Prior to the March 2025 Security Maintenance Release, these malicious actors can update the MAC address of the device, leading to potential exploitation and compromise of user data. It is critical for users to ensure their devices are updated to safeguard against such vulnerabilities.

Affected Version(s)

Samsung Mobile Devices SMR Mar-2025 Release in Android Watch 14

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.