CVE-2022-36873: Samsung Galaxy Watch Plugin

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.

Affected products

  • Samsung Galaxy Watch Plugin: before 2.2.11.22081151 (fixed in 2.2.11.22081151)

Published 2022-09-09. Last modified 2026-06-17.