Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.
References
| Link | Resource |
|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-03-06 05:15
Updated : 2026-02-02 18:14
NVD link : CVE-2025-20912
Mitre link : CVE-2025-20912
CVE.ORG link : CVE-2025-20912
JSON object : View
Products Affected
samsung
- wear_os
- galaxy_watch_5_pro
- galaxy_watch_ultra
- galaxy_watch_5
- galaxy_watch_4_classic
- galaxy_watch_6_classic
- galaxy_watch
- galaxy_watch_4
- galaxy_watch_7
- galaxy_watch_fe
- galaxy_watch_6
CWE
CWE-922
Insecure Storage of Sensitive Information
