Executive brief
A security vulnerability exists in Samsung Galaxy Watch devices that could allow a local attacker to execute unauthorized code with high-level system privileges. This issue stems from how the device validates certain inputs within its internal functions. If exploited, an attacker could potentially gain full control over the device's software, compromising user data and device integrity.
Technical details
An improper input validation vulnerability exists in the FacAtFunction component of Samsung Galaxy Watch firmware. The flaw allows a local attacker to bypass security checks and execute arbitrary code with elevated 'system' privileges. The vulnerability affects Galaxy Watch models running Android Watch versions 14 and 16. Samsung has addressed this issue in the SMR May-2026 Release 1 by implementing proper input validation logic within the affected function. Exploitation requires local access to the device but does not require specific user interaction or prior administrative privileges.
Affected products
- Samsung Galaxy Watch Prior to SMR May-2026 Release 1 (Android Watch 14, 16)
Timeline
- 2026-05-13: disclosed: Privately disclosed to Samsung
- 2026-05-13: advisory
- 2026-05-13: patched: Fixed in SMR May-2026 Release 1