Executive brief
Samsung's Watch Plugin for Android Wear devices contains an access control flaw that allows local attackers to view sensitive information that should be protected. This vulnerability affects Android Watch versions before 17 and could expose personal data stored or processed on smartwatches and wearable devices.
Technical details
The vulnerability is an improper access control flaw in the Watch Plugin component of Samsung's Android Watch platform. The affected component fails to properly restrict access to sensitive information, allowing a local attacker with access to the device to read protected data. Attack requires local access to the wearable device and no network connectivity is needed. The flaw allows unauthorized disclosure of sensitive user information processed or stored on the watch. Samsung has released patched versions (Android Watch 17 and later) that implement proper access control checks.
Affected products
- Samsung Android Watch prior to version 17
Timeline
- 2026-09-09: disclosed: Published on NVD and Samsung Mobile Security site