Improper Access Control in ScreenCapture for Galaxy Watch by Samsung
CVE-2025-20986

5.5MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
4 June 2025

What is CVE-2025-20986?

An improper access control vulnerability has been identified in the ScreenCapture feature of the Galaxy Watch devices, which allows local attackers to exploit the system prior to the June 2025 Release 1 updates. This flaw potentially enables unauthorized users to take screenshots, compromising sensitive information displayed on the device. Users are strongly encouraged to apply the latest security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Samsung Mobile Devices SMR Jun-2025 Release in Android Watch 14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20986 : Improper Access Control in ScreenCapture for Galaxy Watch by Samsung