Vulnerability Details CVE-2025-20998
Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.7%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2025-20998
-
cpe:2.3:h:samsung:galaxy_watch:-
-
cpe:2.3:h:samsung:galaxy_watch_4:-
-
cpe:2.3:h:samsung:galaxy_watch_4_classic:-
-
cpe:2.3:h:samsung:galaxy_watch_5:-
-
cpe:2.3:h:samsung:galaxy_watch_5_pro:-
-
cpe:2.3:h:samsung:galaxy_watch_6:-
-
cpe:2.3:h:samsung:galaxy_watch_6_classic:-
-
cpe:2.3:h:samsung:galaxy_watch_7:-
-
cpe:2.3:h:samsung:galaxy_watch_fe:-
-
cpe:2.3:h:samsung:galaxy_watch_ultra:-
-
cpe:2.3:o:samsung:wear_os:5.0