CVE-2026-20415: Double Free
In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363254; Issue ID: MSV-5617.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20415?
CVE-2026-20415 is classified as a high-severity vulnerability due to its potential for local denial of service.
How do I fix CVE-2026-20415?
To fix CVE-2026-20415, apply the patch identified as ALPS10363254 provided by the vendor.
Who is affected by CVE-2026-20415?
CVE-2026-20415 affects Google Android version 15.0, specifically on devices utilizing certain MediaTek chipsets.
What type of attack does CVE-2026-20415 enable?
CVE-2026-20415 allows for a local denial of service attack if the attacker has already obtained System privileges.
Is user interaction required to exploit CVE-2026-20415?
No, user interaction is not needed for the exploitation of CVE-2026-20415.