CVE-2025-20939: Medium severity Samsung Galaxy Watch vulnerability
Improper authorization in wireless download protocol in Galaxy Watch prior to SMR Apr-2025 Release 1 allows physical attackers to update device unique identifier of Watch devices.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20939?
CVE-2025-20939 is classified as a high severity vulnerability due to its potential to allow unauthorized physical access to device identifiers.
How do I fix CVE-2025-20939?
To fix CVE-2025-20939, update your Galaxy Watch to the SMR Apr-2025 Release 1 or later.
Who is affected by CVE-2025-20939?
CVE-2025-20939 affects all Galaxy Watch devices running a version prior to SMR Apr-2025 Release 1.
What happens if CVE-2025-20939 is exploited?
If exploited, CVE-2025-20939 may allow attackers to change the unique identifier of the Galaxy Watch, potentially enabling further unauthorized access.
Is there a workaround for CVE-2025-20939?
There are no known workarounds for CVE-2025-20939, so users must apply the relevant software update to mitigate the risk.