CVE-2025-21023: Low severity Samsung Galaxy Watch vulnerability
Published Aug 6, 2025
·Updated
Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.
Affected Software
1 affected component
Samsung Galaxy Watch<Android Watch 16
Event History
Aug 6, 2025
CVE Published
via MITRE·04:23 AM
Data Sourced
via MITRE·04:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-21023?
CVE-2025-21023 is classified as a critical severity vulnerability due to its potential for local attackers to access sensitive information.
2
How do I fix CVE-2025-21023?
To fix CVE-2025-21023, update your Samsung Galaxy Watch to Android Watch 16 or later to ensure proper access control.
3
What devices are affected by CVE-2025-21023?
CVE-2025-21023 affects Samsung Galaxy Watch devices running versions prior to Android Watch 16.
4
Can CVE-2025-21023 be exploited remotely?
CVE-2025-21023 requires local access, meaning it cannot be exploited remotely.
5
What kind of sensitive information is at risk in CVE-2025-21023?
CVE-2025-21023 allows local attackers to potentially access sensitive data stored on the Samsung Galaxy Watch.