CVE-2025-21004: Medium severity Samsung Galaxy Watch vulnerability
Published Jul 8, 2025
·Updated
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.
Affected Software
12 affected components
Samsung Galaxy Watch
All of the following
Samsung Wear Os=5.0
Any of the following
Samsung Galaxy Watch
Samsung Galaxy Watch 4
Samsung Galaxy Watch 4 Classic
Samsung Galaxy Watch 5
Samsung Galaxy Watch 5 Pro
Samsung Galaxy Watch 6
Samsung Galaxy Watch 6 Classic
Samsung Galaxy Watch 7
Samsung Galaxy Watch Fe
Samsung Galaxy Watch Ultra
Event History
Jul 8, 2025
CVE Published
via MITRE·10:34 AM
Data Sourced
via MITRE·10:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21004?
CVE-2025-21004 is classified as a high-severity vulnerability due to its potential to allow local attackers to power off the Galaxy Watch.
2
How do I fix CVE-2025-21004?
To fix CVE-2025-21004, ensure that your Galaxy Watch is updated to the latest software version available as of SMR Jul-2025 Release 1.
3
Who is affected by CVE-2025-21004?
CVE-2025-21004 affects all versions of Samsung Galaxy Watch prior to SMR Jul-2025 Release 1.
4
What type of attack does CVE-2025-21004 enable?
CVE-2025-21004 enables local attackers to execute a denial-of-service attack by powering off the device.
5
Can CVE-2025-21004 be exploited remotely?
CVE-2025-21004 cannot be exploited remotely, as it requires physical access to the Galaxy Watch.