ملاحظة: كان رمز الثغرة البرمجية
SVE-2025-1926
CVE-2026-20989
"كان النظام يسمح بتمرير وتثبيت ملفات خطوط الخارجية بصيغة .ttf دون التحقق "
بعد سد الثغرة؛
" أصبح يرفض قطعيًا تثبيت أو تفعيل أي خط لا يمتلك توقيعًا تشفيريًا رقميًا معتمدًا ورسميًا إما من Samsung نفسها أو من شريكتها Monotype"
Post summary
The post highlights CVE-2026-20989, describing its exploitation via unverified .ttf font installation and confirms that a patch has been applied, disabling the vulnerability with no evidence of exploitation.
ONEUI March Security Update patched vulnerability SVE-2025-1926(CVE-2026-20989), disallowing installation of system-wide font styles using .ttf files that lack an official Samsung/Monotype cryptographic signature due to security concerns, meaning users are now no longer allowed to install any fonts from outside the Galaxy Store app as their system font.
While being a safety measure, this change limits the customizability of Galaxy devices and restricts the users' freedom. Moreover, this change may even hinder user experience for some people completely – for example, the Galaxy Store does not feature any dyslexia-friendly fonts, which is a big issue for dyslexic people who may have bought their Galaxy device expecting to just install a third-party dyslexia-friendly font on it.
The users should be provided with an option, after being warned about the dangers of doing so and at their own risk, to disable this security feature and be able to install system-wide font styles using .ttf files that do not have the Samsung/Monotype cryptographic signature (just like it is with downloading apps from third-party.apk files), as was possible before the March Security Update.
https://eu.community.samsung.com/t5/mobile-apps-services/allowing-installation-of-font-styles-from-third-party-ttf-files/td-p/14511446/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufE1PMjZHQzRDVFRWSjE3fDE0NTM2NTgxfFNVQlNDUklQVElPTlN8aEs
@SamsungMobile@SamsungMobileUS@SamsungTurkiye@tarunvats33
Post summary
The post announces that Samsung’s March Security Update patches CVE-2026-20989, limiting system font installations to officially signed files, and offers users a workaround by disabling the restriction.
CVE-2026-20989 Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font. https://www.cve.org/CVERecord?id=CVE-2026-20989
Post summary
The text announces CVE-2026-20989, describing improper verification of cryptographic signatures in Font Settings that could let physical attackers install custom fonts; no PoC, exploit, patch, or active exploitation details are provided.