CVE-2025-20998: Medium severity Samsung SamsungAccount vulnerability
Published Jul 8, 2025
·Updated
Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.
Affected Software
12 affected components
Samsung SamsungAccount<SMR Jul-2025 Release 1
All of the following
Samsung Wear Os=5.0
Any of the following
Samsung Galaxy Watch
Samsung Galaxy Watch 4
Samsung Galaxy Watch 4 Classic
Samsung Galaxy Watch 5
Samsung Galaxy Watch 5 Pro
Samsung Galaxy Watch 6
Samsung Galaxy Watch 6 Classic
Samsung Galaxy Watch 7
Samsung Galaxy Watch Fe
Samsung Galaxy Watch Ultra
Event History
Jul 8, 2025
CVE Published
via MITRE·10:34 AM
Data Sourced
via MITRE·10:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20998?
CVE-2025-20998 is classified as a medium severity vulnerability due to improper access control.
2
How do I fix CVE-2025-20998?
To mitigate CVE-2025-20998, update the SamsungAccount software to the SMR Jul-2025 Release 1 version.
3
Which devices are affected by CVE-2025-20998?
CVE-2025-20998 affects Galaxy Watch devices running SamsungAccount prior to SMR Jul-2025 Release 1.
4
What type of attack can exploit CVE-2025-20998?
CVE-2025-20998 can be exploited by local attackers to gain unauthorized access to a user's phone number.
5
Is there a patch available for CVE-2025-20998?
Yes, a patch is available by updating to SamsungAccount version SMR Jul-2025 Release 1.