Board-level USB access now opens passcode-protected data on 24 Galaxy Watch models.
The method needs possession of the watch, disassembly and a connection to its USB test pads.
Affects
Samsung Galaxy Watch FE and Watch 4, 5, and 6 families running Wear OS, using Exynos W920 or W930 SoCs.
What it enables
Passcode recovery and decrypted application-data extraction
Obtain and disassemble a supported Galaxy Watch.→↓Connect the forensic workstation to the watch's USB test pads.→↓Use Passware Kit Mobile 2026 v5 to exercise the Exynos W920/W930 vulnerability and acquire the protected material.→↓Run GPU-accelerated passcode recovery.→↓Use the recovered passcode to decrypt application data.
Why this matters
A stolen locked watch can no longer be assumed to keep its application data confidential once an equipped examiner reaches the board.
Detail and 2 sources
Required access
Device in hand, watch disassembled, and a USB connection made to board test pads
Affected versions
Galaxy Watch FE on Wear OS 4.x–6.x, Galaxy Watch4 and Watch4 Classic on Wear OS 3.x–6.x, Galaxy Watch5 and Watch5 Pro on Wear OS 3.x–6.x, Galaxy Watch6 and Watch6 Classic on Wear OS 4.x–6.x
Proof of concept
Demonstrated by the researcher
Passware’s commercial tool exploits an undisclosed vulnerability in the Exynos W920 and W930 system-on-chips to acquire protected material.
It then performs GPU-accelerated passcode recovery and uses the recovered passcode to decrypt application data.
The reviewed announcement and device catalog do not identify a remediation for affected watches.
Evidence
Passware's October 1 release announcement states that the shipped commercial tool exploits the two SoCs after disassembly and test-pad connection, recovers passcodes, decrypts app data, and gives a measured Watch6 recovery rate.Passware's supported-device catalog names the model and Wear OS ranges.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.