Improper Access Control Vulnerability in Samsung Android Watch Plugin
CVE-2026-21109

2.1LOW

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21109?

An improper access control vulnerability in the Samsung Android Watch Plugin allows local attackers to gain unauthorized access to sensitive user information. This issue can be exploited by an authenticated user to retrieve private data, potentially compromising the security and privacy of the affected device. Users are encouraged to update to the latest version of the Android Watch Plugin to mitigate this threat.

Affected Version(s)

Watch Plugin Android Watch 17

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.