Description
Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information.
Published: 2026-09-09
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure
Action: Apply Patch
AI Analysis

Impact

An improper access control flaw exists in the Samsung Watch Plugin version preceding Android Watch 17. This weakness allows a local attacker with access to the watch device to read information that should be restricted. The impact is limited to data confidentiality, as there is no escalation to remote code execution or denial of service. The flaw is classified as an access control issue.

Affected Systems

The Samsung Mobile Watch Plugin for devices running Android Watch prior to version 17 is affected. No specific sub‑version ranges are listed in the CNA data, so any build of the plugin before the official update is presumed vulnerable.

Risk and Exploitability

The CVSS score of 2.1 indicates low overall severity, reflecting a narrow execution context and lack of extensive impact. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not flagged in the CISA KEV catalog, suggesting no confirmed exploitation has been observed yet. Attackers would need local access to the device, for example by physically connecting or using the watch’s own software interface, to exploit the control weakness and read sensitive data.

Generated by OpenCVE AI on September 9, 2026 at 10:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Samsung Watch Plugin to a version that includes the access control fix
  • Enforce strict access controls on the plugin, restricting which applications or services can query its data
  • Limit local access to the watch by using device lockdown or enforcing a secure user profile

Generated by OpenCVE AI on September 9, 2026 at 10:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile watch Plugin
Vendors & Products Samsung Mobile
Samsung Mobile watch Plugin

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in Samsung Watch Plugin
Weaknesses CWE-284

Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Watch Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-09-10T14:13:14.407Z

Reserved: 2025-12-11T01:33:35.830Z

Link: CVE-2026-21109

cve-icon Vulnrichment

Updated: 2026-09-10T14:13:08.524Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T05:17:23.373

Modified: 2026-09-10T15:17:28.850

Link: CVE-2026-21109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:22Z

Weaknesses