CVE-2025-20912: Medium severity Samsung Galaxy Watch vulnerability
Published Mar 6, 2025
·Updated
Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.
Affected Software
12 affected components
Samsung Galaxy Watch
All of the following
Samsung Wear Os=5.0
Any of the following
Samsung Galaxy Watch
Samsung Galaxy Watch 4
Samsung Galaxy Watch 4 Classic
Samsung Galaxy Watch 5
Samsung Galaxy Watch 5 Pro
Samsung Galaxy Watch 6
Samsung Galaxy Watch 6 Classic
Samsung Galaxy Watch 7
Samsung Galaxy Watch Fe
Samsung Galaxy Watch Ultra
Event History
Mar 6, 2025
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20912?
CVE-2025-20912 is considered a high severity vulnerability due to its potential impact on local data access by unauthorized users.
2
How do I fix CVE-2025-20912?
To fix CVE-2025-20912, update the DiagMonAgent to the latest version available in the SMR Mar-2025 Release 1.
3
What devices are affected by CVE-2025-20912?
CVE-2025-20912 affects Samsung Galaxy Watch devices prior to the SMR Mar-2025 Release 1.
4
What type of attack does CVE-2025-20912 enable?
CVE-2025-20912 enables local attackers to gain unauthorized access to sensitive data on the Galaxy Watch.
5
Is there a public disclosure for CVE-2025-20912?
Yes, CVE-2025-20912 has been publicly disclosed through security advisories related to Samsung Galaxy Watch vulnerabilities.