CVE-2026-20989Patch(samsung / android)

LOWCVSS 2.4 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch samsung android systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
android

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-17: 1Mentions · 2026-04-23: 1Mentions · 2026-05-17: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-05-17: 1Technical Details · 2026-03-17: 1Technical Details · 2026-04-23: 1Technical Details · 2026-05-17: 103-1704-2305-17
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-171
Disclosure1
2026-04-231
Patch1
2026-05-171
Patch1
Full discourse3 posts
  • 𝐍𝐀|𝐒𝐆@NA1XF1
    Patch

    ملاحظة: كان رمز الثغرة البرمجية ​SVE-2025-1926 ​CVE-2026-20989 "كان النظام يسمح بتمرير وتثبيت ملفات خطوط الخارجية بصيغة .ttf دون التحقق " بعد سد الثغرة؛ " أصبح يرفض قطعيًا تثبيت أو تفعيل أي خط لا يمتلك توقيعًا تشفيريًا رقميًا معتمدًا ورسميًا إما من Samsung نفسها أو من شريكتها Monotype"

    Post summary

    The post highlights CVE-2026-20989, describing its exploitation via unverified .ttf font installation and confirms that a patch has been applied, disabling the vulnerability with no evidence of exploitation.

    20081972
    704 followersView on X
  • Teşkilat-ı Sinaloa@Fandroidmen
    Patch

    ONEUI March Security Update patched vulnerability SVE-2025-1926(CVE-2026-20989), disallowing installation of system-wide font styles using .ttf files that lack an official Samsung/Monotype cryptographic signature due to security concerns, meaning users are now no longer allowed to install any fonts from outside the Galaxy Store app as their system font. While being a safety measure, this change limits the customizability of Galaxy devices and restricts the users' freedom. Moreover, this change may even hinder user experience for some people completely – for example, the Galaxy Store does not feature any dyslexia-friendly fonts, which is a big issue for dyslexic people who may have bought their Galaxy device expecting to just install a third-party dyslexia-friendly font on it. The users should be provided with an option, after being warned about the dangers of doing so and at their own risk, to disable this security feature and be able to install system-wide font styles using .ttf files that do not have the Samsung/Monotype cryptographic signature (just like it is with downloading apps from third-party.apk files), as was possible before the March Security Update. https://eu.community.samsung.com/t5/mobile-apps-services/allowing-installation-of-font-styles-from-third-party-ttf-files/td-p/14511446/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufE1PMjZHQzRDVFRWSjE3fDE0NTM2NTgxfFNVQlNDUklQVElPTlN8aEs @SamsungMobile @SamsungMobileUS @SamsungTurkiye @tarunvats33

    Post summary

    The post announces that Samsung’s March Security Update patches CVE-2026-20989, limiting system font installations to officially signed files, and offers users a workaround by disabling the restriction.

    00000132
    552 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20989 Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font. https://www.cve.org/CVERecord?id=CVE-2026-20989

    Post summary

    The text announces CVE-2026-20989, describing improper verification of cryptographic signatures in Font Settings that could let physical attackers install custom fonts; no PoC, exploit, patch, or active exploitation details are provided.

    00000149
    56.7K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--

Explore more