CVE-2026-20507: Use After Free
In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9125.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11191981
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Exposure is limited to systems using the Audio HAL component. Exploitation requires an attacker to have already obtained System privilege, so it is primarily relevant as a post-compromise privilege-escalation path.
Is user interaction required for exploitation?
No. The issue can be exploited without user interaction once the attacker has the required System privilege.
What identifiers can be used to track remediation?
The vendor patch identifier is ALPS11191981, and the associated issue identifier is MSV-9125.