CVE-2026-20979
EUVD-2026-539704.02.2026, 07:15
Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| samsung | android | 15.0 |
| samsung | android | 15.0:smr-apr-2025-r1 |
| samsung | android | 15.0:smr-aug-2025-r1 |
| samsung | android | 15.0:smr-dec-2025-r1 |
| samsung | android | 15.0:smr-feb-2025-r1 |
| samsung | android | 15.0:smr-jan-2025-r1 |
| samsung | android | 15.0:smr-jan-2026-r1 |
| samsung | android | 15.0:smr-jul-2025-r1 |
| samsung | android | 15.0:smr-jun-2025-r1 |
| samsung | android | 15.0:smr-mar-2025-r1 |
| samsung | android | 15.0:smr-may-2025-r1 |
| samsung | android | 15.0:smr-nov-2025-r1 |
| samsung | android | 15.0:smr-oct-2025-r1 |
| samsung | android | 15.0:smr-sep-2025-r1 |
| samsung | android | 16.0 |
| samsung | android | 16.0:smr-aug-2025-r1 |
| samsung | android | 16.0:smr-dec-2025-r1 |
| samsung | android | 16.0:smr-jan-2026-r1 |
| samsung | android | 16.0:smr-nov-2025-r1 |
| samsung | android | 16.0:smr-oct-2025-r1 |
| samsung | android | 16.0:smr-sep-2025-r1 |
𝑥
= Vulnerable software versions