CVE-2026-20988
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
16/03/2026
Last modified:
16/03/2026
Description
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.
Impact
Base Score 4.0
6.80
Severity 4.0
MEDIUM



