Improper Intent Verification in Galaxy Watch System UI by Samsung
CVE-2025-21004

6.2MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
8 July 2025

What is CVE-2025-21004?

The Galaxy Watch's System UI contains an improperly verified broadcast receiver, which allows local attackers to execute malicious actions. This vulnerability enables attackers to power off the device by exploiting the flawed intent verification process. Users should ensure their devices are updated to the latest SMR Jul-2025 Release 1 to mitigate this risk.

Affected Version(s)

Samsung Mobile Devices SMR Jul-2025 Release in Android Watch 14

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-21004 : Improper Intent Verification in Galaxy Watch System UI by Samsung