CVE-2026-20409: High severity Google Android vulnerability
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363246; Issue ID: MSV-5779.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20409?
CVE-2026-20409 has a high severity due to the potential for local privilege escalation.
How do I fix CVE-2026-20409?
To fix CVE-2026-20409, apply the patch with ID ALPS10363246 as soon as it becomes available.
Who is affected by CVE-2026-20409?
CVE-2026-20409 primarily affects devices running Google Android version 15.0.
Can CVE-2026-20409 be exploited without user interaction?
Yes, CVE-2026-20409 can be exploited without user interaction if an attacker has obtained System privileges.
What causes CVE-2026-20409?
CVE-2026-20409 is caused by a possible out of bounds write due to a missing bounds check in imgsys.