Junglewise Threat Intelligence

CVE-2026-21013: Samsung Galaxy Wearable incorrect default permissions

CVE-2026-21013 · Severity: medium · CVSS 5.5 · Published 2026-04-13

Vendors: Samsung.

Executive brief

The Samsung Galaxy Wearable application, used to manage smartwatches and earbuds, contained a security flaw where sensitive information was not properly protected. A malicious application installed on the same device could exploit this to access private user data. Samsung has released an update to correct these permissions and secure the data.

Technical details

A vulnerability classified as Incorrect Default Permissions (CWE-276) exists in the Samsung Galaxy Wearable application. Due to improperly configured access controls, a local malicious actor or application on the same device can bypass intended restrictions to read sensitive data handled by the app. The attack requires local access but no specific user interaction. Samsung addressed this in version 2.2.68.26 by implementing stricter permission requirements for accessing the affected components.

Affected products

  • Samsung Galaxy Wearable prior to 2.2.68.26

Timeline

  • 2026-04-07: advisory: Samsung published the security bulletin.
  • 2026-04-13: disclosed: CVE published to NVD.

References