Medium severity6.5NVD Advisory· Published Jan 22, 2020· Updated Jun 17, 2026
CVE-2018-16271
CVE-2018-16271
Description
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
Affected products
13- Samsung/Galaxy Gear seriesdescription
- Range: < RE2
- Range: < RE2
- cpe:2.3:o:samsung:galaxy_gear_firmware:*:*:*:*:*:*:*:*Range: <re2
- cpe:2.3:o:samsung:gear_fit_2_pro_firmware:*:*:*:*:*:*:*:*Range: <re2
Patches
Vulnerability mechanics
References
2- media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdfnvdExploitThird Party Advisory
- www.youtube.com/watchnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.