CVE-2025-20910: Medium severity Samsung Galaxy Watch Gallery vulnerability
Published Mar 6, 2025
·Updated
Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.
Affected Software
12 affected components
Samsung Galaxy Watch Gallery<SMR Mar-2025 Release 1
All of the following
Samsung Wear Os=5.0
Any of the following
Samsung Galaxy Watch
Samsung Galaxy Watch 4
Samsung Galaxy Watch 4 Classic
Samsung Galaxy Watch 5
Samsung Galaxy Watch 5 Pro
Samsung Galaxy Watch 6
Samsung Galaxy Watch 6 Classic
Samsung Galaxy Watch 7
Samsung Galaxy Watch Fe
Samsung Galaxy Watch Ultra
Event History
Mar 6, 2025
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20910?
CVE-2025-20910 is classified as a medium severity vulnerability due to incorrect default permissions allowing unauthorized data access.
2
How do I fix CVE-2025-20910?
To fix CVE-2025-20910, update your Galaxy Watch Gallery to the SMR Mar-2025 Release 1 or later.
3
What data is at risk due to CVE-2025-20910?
CVE-2025-20910 could potentially expose private user data stored in the Galaxy Watch Gallery.
4
Who is affected by CVE-2025-20910?
Users of Samsung Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 are affected by CVE-2025-20910.
5
Can CVE-2025-20910 be exploited remotely?
CVE-2025-20910 cannot be exploited remotely as it requires local access to the device for attackers.