CVE-2026-20412: High severity Google Android vulnerability
In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue ID: MSV-5733.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20412?
CVE-2026-20412 is classified as having a high severity due to the potential for local escalation of privilege without user interaction.
How do I fix CVE-2026-20412?
To fix CVE-2026-20412, apply the patch identified as ALPS10351676 provided by the software vendor.
Can CVE-2026-20412 be exploited remotely?
CVE-2026-20412 cannot be exploited remotely as it requires the attacker to have already obtained System privileges.
What software versions are affected by CVE-2026-20412?
CVE-2026-20412 affects Google Android versions 13.0, 14.0, 15.0, and 16.0.
Is user interaction needed to exploit CVE-2026-20412?
No, user interaction is not needed to exploit CVE-2026-20412.