Improper Access Control in Samsung Galaxy Watch Products
CVE-2025-21023

3.3LOW

Key Information:

Vendor

Samsung

Vendor
CVE Published:
6 August 2025

What is CVE-2025-21023?

An access control issue in the WcsExtension component of Samsung Galaxy Watch devices prior to Android Watch 16 enables local attackers to gain unauthorized access to sensitive information. This vulnerability highlights the potential risks of improper security mechanisms that may expose user data under certain conditions.

Affected Version(s)

WcsExtension for Galaxy Watch Android Watch 16

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.