Impact
An improper access control flaw exists in the Samsung Watch Plugin version preceding Android Watch 17. This weakness allows a local attacker with access to the watch device to read information that should be restricted. The impact is limited to data confidentiality, as there is no escalation to remote code execution or denial of service. The flaw is classified as an access control issue.
Affected Systems
The Samsung Mobile Watch Plugin for devices running Android Watch prior to version 17 is affected. No specific sub‑version ranges are listed in the CNA data, so any build of the plugin before the official update is presumed vulnerable.
Risk and Exploitability
The CVSS score of 2.1 indicates low overall severity, reflecting a narrow execution context and lack of extensive impact. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not flagged in the CISA KEV catalog, suggesting no confirmed exploitation has been observed yet. Attackers would need local access to the device, for example by physically connecting or using the watch’s own software interface, to exploit the control weakness and read sensitive data.
OpenCVE Enrichment