Medium severity5.0NVD Advisory· Published Mar 16, 2026· Updated Jun 17, 2026
CVE-2026-20988
CVE-2026-20988
Description
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:o:samsung:android:16.0:-:*:*:*:*:*:*+ 7 more
- cpe:2.3:o:samsung:android:16.0:-:*:*:*:*:*:*
- cpe:2.3:o:samsung:android:16.0:smr-aug-2025-r1:*:*:*:*:*:*
- cpe:2.3:o:samsung:android:16.0:smr-dec-2025-r1:*:*:*:*:*:*
- cpe:2.3:o:samsung:android:16.0:smr-feb-2026-r1:*:*:*:*:*:*
- cpe:2.3:o:samsung:android:16.0:smr-jan-2026-r1:*:*:*:*:*:*
- cpe:2.3:o:samsung:android:16.0:smr-nov-2025-r1:*:*:*:*:*:*
- cpe:2.3:o:samsung:android:16.0:smr-oct-2025-r1:*:*:*:*:*:*
- cpe:2.3:o:samsung:android:16.0:smr-sep-2025-r1:*:*:*:*:*:*
- Range: < SMR Mar-2026 Release 1
- Range: SMR Mar-2026 Release in Android 16
Patches
Vulnerability mechanics
References
1- security.samsungmobile.com/securityUpdate.smsbnvdVendor Advisory
News mentions
0No linked articles in our index yet.