
CVE-2026-20992 Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application. https://www.cve.org/CVERecord?id=CVE-2026-20992
Post summary
The statement announces CVE-2026-20992 as an improper authorization flaw that permits local attackers to disable background data usage settings, without providing additional evidence such as PoC, exploit code, or patch information.
