This is pretty terrible stuff.
"As both Sand and Xplora note, exploiting this backdoor would be difficult, since it requires knowledge of both the unique factory-set encryption key and the phone number assigned to the watch. For that reason, there’s no reason for people who own a vulnerable device to panic."
Yeah don't panic, because it would be hard for anyone else to activate these features ...
But it would be easy for the folks who added them to do so.