First published: Fri Jun 11 2021(Updated: )
Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Gear S | <2.2.05.20122441 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25406 is an information exposure vulnerability in Gear S Plugin.
The severity of CVE-2021-25406 is medium with a CVSS score of 6.5.
CVE-2021-25406 affects Samsung Gear S devices running versions up to 2.2.05.20122441 of Gear S Plugin.
Untrusted applications can exploit CVE-2021-25406 to access connected BT device information on affected Samsung Gear S devices.
To fix CVE-2021-25406, users should update Gear S Plugin to version 2.2.05.20122441 or later.