Description

Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.

INFO

Published Date :

2026-03-16T04:31:53.810Z

Last Modified :

2026-03-17T03:55:31.506Z

Source :

SamsungMobile
AFFECTED PRODUCTS

The following products are affected by CVE-2026-20988 vulnerability.

Vendors Products
Samsung Mobile
  • Samsung Mobile Devices
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-20988.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability