
CVE-2026-20988 Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings pri… https://www.cve.org/CVERecord?id=CVE-2026-20988
Post summary
The CVE-2026-20988 disclosure notes that improper intent verification in the Settings app allows a local attacker to trigger arbitrary activities; no PoC, exploit, or patch details are provided in the excerpt.
