Improper Access Control in Galaxy Watch by Samsung
CVE-2025-21012

5.5MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
6 August 2025

What is CVE-2025-21012?

An improper access control vulnerability has been identified in the fall detection feature of Samsung's Galaxy Watch models prior to the SMR Aug-2025 Release 1. This flaw allows local attackers to gain unauthorized access and modify the fall detection configuration, potentially impairing the device's safety mechanisms. It is critical for users to ensure their devices are updated to the latest security patches to mitigate this risk. For further details, refer to the official Samsung security update page.

Affected Version(s)

Samsung Mobile Devices SMR Aug-2025 Release in Android Watch 16

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.