CVE-2025-21045: Medium severity Samsung Galaxy Watch vulnerability
Published Oct 10, 2025
·Updated
Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.
Affected Software
12 affected components
Samsung Galaxy Watch<SMR Oct-2025 Release 1
All of the following
Samsung Wear Os=5.0
Any of the following
Samsung Galaxy Watch
Samsung Galaxy Watch 4
Samsung Galaxy Watch 4 Classic
Samsung Galaxy Watch 5
Samsung Galaxy Watch 5 Pro
Samsung Galaxy Watch 6
Samsung Galaxy Watch 6 Classic
Samsung Galaxy Watch 7
Samsung Galaxy Watch Fe
Samsung Galaxy Watch Ultra
Event History
Oct 10, 2025
CVE Published
via MITRE·06:33 AM
Data Sourced
via MITRE·06:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21045?
CVE-2025-21045 is classified as a moderate severity vulnerability due to the potential for local attackers to access sensitive information.
2
How do I fix CVE-2025-21045?
To remediate CVE-2025-21045, update your Samsung Galaxy Watch to the SMR Oct-2025 Release 1 or later version.
3
Which devices are affected by CVE-2025-21045?
CVE-2025-21045 affects Samsung Galaxy Watch devices prior to the SMR Oct-2025 Release 1.
4
What type of information is at risk due to CVE-2025-21045?
CVE-2025-21045 exposes sensitive information stored insecurely on affected Galaxy Watch models.
5
Can CVE-2025-21045 be exploited remotely?
No, CVE-2025-21045 requires local access for exploitation.