CVE-2025-20945: Medium severity Samsung Galaxy Watch vulnerability
Published Apr 8, 2025
·Updated
Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.
Affected Software
12 affected components
Samsung Galaxy Watch<SMR Apr-2025 Release 1
All of the following
Samsung Wear Os=5.0
Any of the following
Samsung Galaxy Watch
Samsung Galaxy Watch 4
Samsung Galaxy Watch 4 Classic
Samsung Galaxy Watch 5
Samsung Galaxy Watch 5 Pro
Samsung Galaxy Watch 6
Samsung Galaxy Watch 6 Classic
Samsung Galaxy Watch 7
Samsung Galaxy Watch Fe
Samsung Galaxy Watch Ultra
Event History
Apr 8, 2025
CVE Published
via MITRE·04:40 AM
Data Sourced
via MITRE·04:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20945?
The severity of CVE-2025-20945 is classified as high due to its potential to expose sensitive information.
2
How do I fix CVE-2025-20945?
To fix CVE-2025-20945, update your Galaxy Watch to the SMR Apr-2025 Release 1 version or later.
3
Who is affected by CVE-2025-20945?
CVE-2025-20945 affects all Samsung Galaxy Watch devices prior to the SMR Apr-2025 Release 1.
4
What type of vulnerability is CVE-2025-20945?
CVE-2025-20945 is an improper access control vulnerability allowing unauthorized access to sensitive data.
5
Can CVE-2025-20945 be exploited remotely?
CVE-2025-20945 cannot be exploited remotely; it requires local access to the affected Galaxy Watch.