Improper Verification of Intent in Settings by Samsung
CVE-2026-20988
6.8MEDIUM
What is CVE-2026-20988?
An issue has been identified in Samsung's Settings application where improper verification of intent by the broadcast receiver enables a local attacker to launch arbitrary activities with elevated privileges. This vulnerability requires user interaction to be exploited, allowing malicious users to perform sensitive actions under the guise of legitimate Settings privileges.
Affected Version(s)
Samsung Mobile Devices SMR Mar-2026 Release in Android 16