CVE-2025-20986: Medium severity Samsung Galaxy Watch vulnerability
Published Jun 4, 2025
·Updated
Improper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take screenshots.
Affected Software
12 affected components
Samsung Galaxy Watch<SMR Jun-2025 Release 1
All of the following
Samsung Wear Os=5.0
Any of the following
Samsung Galaxy Watch
Samsung Galaxy Watch 4
Samsung Galaxy Watch 4 Classic
Samsung Galaxy Watch 5
Samsung Galaxy Watch 5 Pro
Samsung Galaxy Watch 6
Samsung Galaxy Watch 6 Classic
Samsung Galaxy Watch 7
Samsung Galaxy Watch Fe
Samsung Galaxy Watch Ultra
Event History
Jun 4, 2025
CVE Published
via MITRE·04:56 AM
Data Sourced
via MITRE·04:56 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20986?
CVE-2025-20986 has been classified as a medium severity vulnerability due to the potential for unauthorized local access.
2
How do I fix CVE-2025-20986?
To mitigate CVE-2025-20986, update your Samsung Galaxy Watch to at least SMR Jun-2025 Release 1.
3
What type of attack does CVE-2025-20986 allow?
CVE-2025-20986 allows local attackers to take unauthorized screenshots on affected Galaxy Watch devices.
4
Which devices are affected by CVE-2025-20986?
CVE-2025-20986 affects Samsung Galaxy Watch devices prior to SMR Jun-2025 Release 1.
5
Is there a workaround for CVE-2025-20986?
Currently, there is no known workaround for CVE-2025-20986 other than applying the necessary software update.