CVE-2026-21013
Received
Received - Intake
Incorrect Default Permissions in Galaxy Wearable Allow Data Access
Publication date: 2026-04-13
Last updated on: 2026-04-16
Assigner: Samsung Mobile
Description
Description
Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | galaxy_wearable | to 2.2.68.26 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |