CVE-2026-20506: Use After Free
Published Sep 7, 2026
·Updated
In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9126.
Affected Software
1 affected component
Android Audio HAL
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11191981
Event History
Sep 7, 2026
CVE Published
via MITRE·01:57 AM
Data Sourced
via MITRE·01:57 AM
DescriptionWeakness
Frequently Asked Questions
1
Can an unprivileged local attacker exploit this issue directly?
The available information states that the malicious actor must already have System privilege. It does not indicate that an unprivileged app or user can directly trigger the escalation.
2
What identifiers should be used to track the vendor fix?
The listed patch identifier is ALPS11191981, and the vendor issue identifier is MSV-9126.