CVE-2026-21109: Samsung Mobile Watch Plugin

Low severity, CVSS 2.1. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information.

Affected products

Published 2026-09-09. Last modified 2026-09-10.