Skip to finding
§
High
Physical — Mobile
Confirmed

Board-level USB access now opens passcode-protected data on 24 Galaxy Watch models.

The method needs possession of the watch, disassembly and a connection to its USB test pads.

Affects

Samsung Galaxy Watch FE and Watch 4, 5, and 6 families running Wear OS, using Exynos W920 or W930 SoCs.

What it enables

Passcode recovery and decrypted application-data extraction

Obtain and disassemble a supported Galaxy Watch.→↓Connect the forensic workstation to the watch's USB test pads.→↓Use Passware Kit Mobile 2026 v5 to exercise the Exynos W920/W930 vulnerability and acquire the protected material.→↓Run GPU-accelerated passcode recovery.→↓Use the recovered passcode to decrypt application data.
Why this matters

A stolen locked watch can no longer be assumed to keep its application data confidential once an equipped examiner reaches the board.

Detail and 2 sources
Required access

Device in hand, watch disassembled, and a USB connection made to board test pads

Affected versions

Galaxy Watch FE on Wear OS 4.x–6.x, Galaxy Watch4 and Watch4 Classic on Wear OS 3.x–6.x, Galaxy Watch5 and Watch5 Pro on Wear OS 3.x–6.x, Galaxy Watch6 and Watch6 Classic on Wear OS 4.x–6.x

Proof of concept

Demonstrated by the researcher

Passware’s commercial tool exploits an undisclosed vulnerability in the Exynos W920 and W930 system-on-chips to acquire protected material.

It then performs GPU-accelerated passcode recovery and uses the recovered passcode to decrypt application data.

The reviewed announcement and device catalog do not identify a remediation for affected watches.

Evidence
Passware's October 1 release announcement states that the shipped commercial tool exploits the two SoCs after disassembly and test-pad connection, recovers passcodes, decrypts app data, and gives a measured Watch6 recovery rate.Passware's supported-device catalog names the model and Wear OS ranges.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, October 5, 2026