First published: Tue Apr 08 2025(Updated: )
Improper handling of exceptional conditions in pairing specific bluetooth devices in Galaxy Watch Bluetooth pairing prior to SMR Apr-2025 Release 1 allows local attackers to pair with specific bluetooth devices without user interaction.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Galaxy Watch | <SMR Apr-2025 Release 1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-20946 is classified as a medium severity vulnerability that allows local attackers to pair with specific Bluetooth devices without user consent.
To mitigate CVE-2025-20946, update your Samsung Galaxy Watch to the latest firmware version SMR Apr-2025 Release 1 or later.
CVE-2025-20946 affects Samsung Galaxy Watch devices that are running firmware versions prior to SMR Apr-2025 Release 1.
The risk associated with CVE-2025-20946 is unauthorized Bluetooth pairing, potentially leading to data exposure or device manipulation.
Users of Samsung Galaxy Watch devices prior to the SMR Apr-2025 Release 1 update are affected by CVE-2025-20946.