CVE-2025-20939

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 8, 2025

Summary

CVE-2025-20939 is a vulnerability affecting the wireless download protocol in Samsung Galaxy Watch devices prior to the SMR Apr-2025 Release 1. This issue allows physical attackers to bypass authorization checks and update the unique identifier of the Watch, potentially leading to unauthorized access or impersonation of the device. This could pose a security risk, as the identifier is used to authenticate and authorize transactions with other devices and services. Successful exploitation of this vulnerability requires proximity to the targeted Watch device. Samsung has released a software update to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share